This release appears healthy and suitable for dependency use: it has a long release history, frequent recent releases, stable versioning, active non-archived organizational backing, and recent commits from 12 contributors. The package is clearly licensed, has a substantial file tree, no install-time lifecycle scripts, and its missing artifact tests and changelog are compensated by repository tests and the package's established TYPO3 project context. The main reservations are the absence of a security policy and security-scanning tooling, plus no recent issue or pull-request activity data, but these do not outweigh the strong maintenance and release evidence.
88%
Total Score
90
100
94
90
No new or closed issues or pull requests were recorded in the last month, and issue totals are unknown. This is a modest transparency gap, but it is outweighed by recent commits and releases.
Composer is used as a build tool, supporting reproducible project structure, but no security-scanning tools were detected. The missing scanning evidence is a hygiene concern rather than evidence of abandonment.
No repository security policy was found, reducing disclosure transparency for security issues. The active organizational project and ongoing maintenance partly compensate, but the gap remains relevant.
| Title | Versions | Severity |
|---|---|---|
CVE-2010-3672 typo3/cms-fluid is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.3.4 and 4.4.0 - 4.4.1. | 0.0.0 - 4.3.44.4.0 - 4.4.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^7.4.8 | — | — |
typo3/cms-core Version 14.3.7 | — | — |
typo3fluid/fluid Version ^5.3.2 | — | — |
typo3/cms-extbase Version 14.3.7 | — | — |
symfony/dependency-injection Version ^7.4.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.