Package Health

typo3/cms-install

This is a mature, actively maintained TYPO3 component with a release history dating back over 9 years, 270 releases, 40 releases in the last 12 months, and a stable current major version. The linked repository is not archived, has been pushed recently, and shows 52 commits from 13 active maintainers over the last 3 months; organization backing and moderate contributor distribution further reduce abandonment and bus-factor risk. Licensing, package structure, repository linkage, and lifecycle hygiene are solid, although the repository has no documented security policy or security-scanning tooling, and issue/ pull-request activity data is limited. Overall, the available evidence supports depending on this release, with normal operational security due diligence recommended.

Latest v14.3.7PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Are you affected? Scan for Free

Health Score Breakdown

Repo issue activitycaution

No new or closed issues or pull requests were recorded in the last month, but the open issue and pull-request counts are unknown; this is a limited coverage gap rather than evidence of abandonment because recent commit and release activity is strong.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected; this is a modest security-process gap in an otherwise active project.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.

Vulnerabilities

TitleVersionsSeverity
CVE-2024-55891
typo3/cms-install is vulnerable to Insertion of Sensitive Information into Log File in versions 13.4.2 - 13.4.2.
13.4.2 - 13.4.2
Low
CVE-2023-47126
typo3/cms-install is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 12.2.0 - 12.4.8.
12.2.0 - 12.4.8
Low
CVE-2010-5100
typo3/cms-install is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.2.0 - 4.2.16, 4.3.0 - 4.3.9 and 4.4.0 - 4.4.5.
4.2.0 - 4.2.164.3.0 - 4.3.94.4.0 - 4.4.5
Low
CVE-2009-3636
typo3/cms-install is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.0.13, 4.1.0 - 4.1.13, 4.2.0 - 4.2.10 and 4.3alpha1 - 4.3beta2.
0.0.0 - 4.0.134.1.0 - 4.1.134.2.0 - 4.2.10 +1 more
Medium
CVE-2010-3671
typo3/cms-install is vulnerable to Session Fixation in versions 0.0.0 - 4.1.14, 4.2.0 - 4.2.13, 4.3.0 - 4.3.4 and 4.4.0 - 4.4.1.
0.0.0 - 4.1.144.2.0 - 4.2.134.3.0 - 4.3.4 +1 more
Medium

Package versions

Maintainers

TYPO3 Core Team

Direct Dependencies

DependencyLast ReleaseScore
doctrine/dbal
Version ~4.4.4
—
—
symfony/finder
Version ^7.4.8
—
—
typo3/cms-core
Version 14.3.7
—
—
typo3/cms-fluid
Version 14.3.7
—
—
nikic/php-parser
Version ^5.4.0
—
—

Weekly Downloads

Info

Last Published
23 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform