This is a mature, stable, actively published TYPO3 extension with a long release history, 40 releases in the last 12 months, a recent repository push, organizational backing, a clear GPL license, and a minimal dependency profile. The main concerns are that only two commits came from one contributor in the last three months, repository security scanning and a security policy are absent, and the artifact omits tests and a changelog; however, repository tests compensate for the missing packaged tests, and the package is not deprecated or archived. Overall, it appears suitable to depend on, with some maintenance and security-process limitations to monitor.
82%
Total Score
70
100
94
90
All two recent commits came from one contributor, creating concentration risk; this is partly mitigated by the repository being owned by the TYPO3-CMS organization.
Only two commits were made in the last three months, showing limited recent activity despite the recent push and strong release history.
No new or closed issues or pull requests were recorded in the last month, which limits evidence of issue responsiveness; open issue and pull-request counts are unknown.
Composer is used as a build tool, but no security scanning tools were detected, leaving a security-process gap.
No repository security policy was detected, reducing transparency about vulnerability reporting and response procedures.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version 14.3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.