The package has a clear license, a matching source repository, and a modest dependency footprint. Organization backing, recent releases, and a changelog provide useful continuity despite limited repository activity.
68%
Total Score
67
100
86
83
A changelog and README are present, but the README is only nine characters long and there are no tests. The missing tests are normal packaging practice, while the extremely limited consumer documentation is a minor transparency gap.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the recent registry releases provide some counterevidence.
There were no new or closed issues or pull requests in the last month. Combined with the lack of recent commits, this indicates limited visible development activity.
Composer is used for builds, but no repository security scanning tools were detected. The missing scanning lowers supply-chain hygiene confidence without proving the package is unsafe.
The repository has no security policy. That weakens transparency around vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.