This is a mature, actively maintained TYPO3 component with a release history dating back over 9 years, 270 releases, 40 releases in the last 12 months, and a stable current major version. The linked repository is not archived, has been pushed recently, and shows 52 commits from 13 active maintainers over the last 3 months; organization backing and moderate contributor distribution further reduce abandonment and bus-factor risk. Licensing, package structure, repository linkage, and lifecycle hygiene are solid, although the repository has no documented security policy or security-scanning tooling, and issue/ pull-request activity data is limited. Overall, the available evidence supports depending on this release, with normal operational security due diligence recommended.
88%
Total Score
90
100
94
88
No new or closed issues or pull requests were recorded in the last month, but the open issue and pull-request counts are unknown; this is a limited coverage gap rather than evidence of abandonment because recent commit and release activity is strong.
Composer build tooling is present, but no security-scanning tools were detected; this is a modest security-process gap in an otherwise active project.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-55891 typo3/cms-install is vulnerable to Insertion of Sensitive Information into Log File in versions 13.4.2 - 13.4.2. | 13.4.2 - 13.4.2 | Low |
CVE-2023-47126 typo3/cms-install is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 12.2.0 - 12.4.8. | 12.2.0 - 12.4.8 | Low |
CVE-2010-5100 typo3/cms-install is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.2.0 - 4.2.16, 4.3.0 - 4.3.9 and 4.4.0 - 4.4.5. | 4.2.0 - 4.2.164.3.0 - 4.3.94.4.0 - 4.4.5 | Low |
CVE-2009-3636 typo3/cms-install is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.0.13, 4.1.0 - 4.1.13, 4.2.0 - 4.2.10 and 4.3alpha1 - 4.3beta2. | 0.0.0 - 4.0.134.1.0 - 4.1.134.2.0 - 4.2.10 +1 more | Medium |
CVE-2010-3671 typo3/cms-install is vulnerable to Session Fixation in versions 0.0.0 - 4.1.14, 4.2.0 - 4.2.13, 4.3.0 - 4.3.4 and 4.4.0 - 4.4.1. | 0.0.0 - 4.1.144.2.0 - 4.2.134.3.0 - 4.3.4 +1 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ~4.4.4 | — | — |
symfony/finder Version ^7.4.8 | — | — |
typo3/cms-core Version 14.3.7 | — | — |
typo3/cms-fluid Version 14.3.7 | — | — |
nikic/php-parser Version ^5.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.