This is a mature, actively maintained TYPO3 extension with 240 releases over about 8 years, 40 releases in the last 12 months, a stable non-prerelease version, no registry deprecation, and a recently updated unarchived repository. The organization-owned TYPO3 project provides meaningful backing, with three active contributors and 13 commits in the last 3 months; the single registry maintainer is therefore not a material concern. The package is licensed, has a coherent file tree and documentation, avoids install-time lifecycle scripts, and has a small focused runtime dependency set. Main limitations are the absence of a repository security policy and security-scanning tooling, plus no repository changelog; the missing packaged tests are compensated by repository tests. Overall, it appears safe to depend on from a maintenance and transparency perspective, with routine supply-chain review still appropriate.
88%
Total Score
100
100
88
90
The artifact includes a README, while packaged tests and a changelog are absent; repository tests compensate for the missing packaged tests, though no provided signal covers the changelog gap.
Composer build tooling is present, but no security-scanning tools were detected; the missing scanning layer is a genuine transparency and security-hygiene gap.
The linked repository has no security policy, leaving vulnerability-reporting and disclosure expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version 14.3.7 | — | — |
typo3/cms-extbase Version 14.3.7 | — | — |
typo3/cms-frontend Version 14.3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.