This is a mature, actively released TYPO3 package with 270 releases since 2017, 40 releases in the last 12 months, a stable non-prerelease version, current repository activity, an unarchived organization-owned repository, and a clear GPL license. The package has a small runtime dependency surface and no install-time lifecycle scripts; its missing packaged tests and changelog are compensated by repository tests, while the main concerns are very low recent commit volume concentrated in one contributor and the absence of a security policy or security-scanning tooling. Overall, it appears suitable to depend on, with normal diligence around the narrow recent contributor activity.
78%
Total Score
67
100
94
88
All 2 recent commits came from one contributor, creating a concentrated recent maintenance profile. The organization-owned TYPO3-CMS repository provides some capacity to hand off maintenance, but no second recent contributor is shown.
The repository recorded only 2 commits in the last 3 months, which is limited relative to the package's release history and warrants caution, although it still demonstrates some recent activity.
Composer build tooling is present, but no security-scanning tools were detected. This is a transparency and assurance gap, though it is not by itself evidence of an unsafe release.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations less explicit than ideal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version 14.3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.