This is a healthy, mature release with a long publication history, frequent recent releases, stable versioning, an active non-archived organizational repository, and distributed recent contribution activity. The package is clearly structured and documented, its repository contains tests, it has a valid GPL license, and it avoids install-time lifecycle scripts. The main concerns are the absence of a repository security policy and security-scanning tooling, plus limited repository popularity; these are transparency and defense-in-depth gaps rather than evidence of abandonment. Several other signals were not collected, so confidence is high but not maximal.
88%
Total Score
100
100
89
90
The repository has only 16 stars and 1 fork, which is limited supporting adoption evidence, though popularity is not decisive and the package has strong release and maintenance evidence.
Composer build tooling is present, but no security-scanning tools were detected; this is a defense-in-depth gap for supply-chain transparency.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-55924 typo3/cms-scheduler is vulnerable to Cross-Site Request Forgery (CSRF) in versions 11.0.0 - 11.5.41. | 11.0.0 - 11.5.41 | High |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version 14.3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.