This is a healthy, mature release with a long history since 2017, 270 releases, 40 releases in the last 12 months, and a stable non-prerelease version. The linked TYPO3 organization repository is active, unarchived, recently pushed, and has 20 commits from six active maintainers in the last three months, providing strong maintenance capacity and a low bus-factor concern. Licensing, packaging, dependency scope, and lifecycle behavior are sound; the artifact lacks packaged tests and a changelog, but repository tests compensate for the former and these are limited transparency gaps. The main remaining concerns are the absence of a repository security policy and security scanning tools, although no dangerous workflows are present.
91%
Total Score
100
100
94
90
Composer is used as a build tool, but no security scanning tools were detected. The missing scanning coverage is a genuine security-hygiene gap, though it does not by itself indicate poor maintenance.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations less transparent for dependents.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-55921 typo3/cms-extensionmanager is vulnerable to Cross-Site Request Forgery (CSRF) in versions 10.0.0 - 10.4.47, 11.0.0 - 11.5.41, 12.0.0 - 12.4.24 and 13.0.0 - 13.4.2. | 10.0.0 - 10.4.4711.0.0 - 11.5.4112.0.0 - 12.4.24 +1 more | High |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version 14.3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.