Package Health

typo3/cms-filemetadata

This is a mature, actively released TYPO3 extension with 270 releases over roughly 9 years, 40 releases in the last 12 months, a stable non-prerelease version, clear GPL licensing, minimal runtime dependencies, and organization backing from TYPO3-CMS. The main concern is that the linked repository reports no commits or active maintainers in the last 3 months, despite the recent registry releases and a very recent repository push; this creates some uncertainty about where ongoing maintenance occurs. The repository also lacks tests, a changelog, security policy, and security scanning, although the very small extension artifact and absence of workflows limit the significance of some of those gaps. Overall, it is usable with moderate maintenance-transparency concerns rather than an abandonment-level risk.

Latest v14.3.7PackagistPackagist

74%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

A README is present, but neither the artifact nor the linked repository contains tests or a changelog. For this very small seven-file extension, the missing tests are a hygiene gap, while the README still documents the repository, issues, documentation, and Packagist locations.

Repo commit activitycaution

The repository reports zero commits and zero active maintainers over the last 3 months, which is a meaningful transparency and maintenance concern. Recent registry releases and the very recent repository push partially offset the concern but do not explain the inactive three-month window.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, and issue counts are unavailable; this provides little evidence of active issue maintenance.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. The missing scanning is a modest hygiene gap rather than a severe risk on its own.

Security policycaution

The repository has no security policy, reducing transparency for vulnerability reporting and response.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

TYPO3 Core Team

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version 14.3.7

Weekly Downloads

Info

Last Published
12 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform