Package Health

typo3/cms-info

This is a mature, actively published TYPO3 component with a release history dating back over 9 years, 270 releases, 40 releases in the last 12 months, and a stable non-prerelease version. It is not deprecated or archived, has a clear GPL license, a focused dependency profile, and repository-backed tests and source files. The main concerns are that only one commit from one contributor was observed in the last 3 months, the repository has no security policy, and repository popularity is modest; organization ownership and the package's strong release cadence provide meaningful compensation, but maintenance activity should still be monitored before adopting it for a critical dependency.

Latest v14.3.7PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Repo bus factorcaution

All observed commits came from one contributor, creating concentration risk. Organization ownership provides some handoff capacity, but no second active contributor was observed in this period.

Repo commit activitycaution

Only 1 commit from 1 active maintainer was observed in the last 3 months, indicating currently thin direct repository activity despite the much stronger recent release history.

Repo issue activitycaution

No new or closed issues or pull requests were observed in the last month, while issue totals are unavailable. This is limited evidence and is not by itself a strong abandonment signal given the package's release cadence.

Repo toolingcaution

Composer is used as a build/dependency tool, but no security scanning tools were detected. The lack of scanning is a security-process gap, though it is not evidence that the package is unsafe or unmaintained.

Security policycaution

No repository security policy was found, which reduces transparency around vulnerability reporting and response expectations.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

TYPO3 Core Team

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version 14.3.7
—
—

Weekly Downloads

Info

Last Published
26 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform