This is a healthy, mature release with a long history, frequent recent releases, stable versioning, active organizational backing, and a non-archived repository. The package is clearly documented and licensed, has a focused runtime dependency set, and its missing packaged tests are compensated by tests in the source repository. Recent repository commit volume is modest, and the repository reports no security scanning or security policy, so it is not entirely risk-free; however, the available evidence supports depending on it, subject to normal review of TYPO3 version compatibility and your own security controls.
88%
Total Score
80
100
94
90
The repository recorded 3 commits from 2 active maintainers in the last 3 months, showing current activity but at a relatively low volume compared with the package's release cadence.
No new or closed issues or pull requests were recorded in the last month, and issue and pull-request totals are unknown. This limits evidence about review activity but is outweighed by frequent package releases and recent commits.
Composer is used as a build tool, but no security scanning tools were detected. The missing scanning evidence is a genuine security-hygiene gap, though it does not indicate abandonment.
The linked repository has no security policy, reducing transparency about vulnerability reporting and response procedures.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version 14.3.7 | — | — |
typo3/cms-fluid Version 14.3.7 | — | — |
typo3/cms-frontend Version 14.3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.