The repository includes tests, a changelog, and a clear MIT license. Maintenance has been quiet for about one year, and no security policy or scanning is reported.
62%
Total Score
88
100
89
88
The package has existed since 2019 with seven releases, but it has had no release in the last 12 months and its median interval is about nine months, indicating slow maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the broader absence of releases in the last year and raising abandonment risk.
Composer build tooling is present, but no security scanning tools are reported. This is a modest transparency and maintenance gap, not evidence that the release is unsafe.
The repository has no security policy. For a package that imports external RSS content, the missing reporting and response process is a real transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms Version ^10.4 || ^11.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.