This release appears healthy and reasonably safe to depend on from a supply-chain health perspective. It is a young but actively maintained package: 12 stable releases in 47 days, 209 commits from 14 active maintainers over three months, recent repository activity, and active pull-request throughput indicate strong current maintenance. The repository is not archived, the package is not deprecated, it has a clear GPL-2.0-or-later license, a substantial artifact and matching source repository, no install lifecycle scripts, and no detected dangerous workflow patterns. The main reservations are the package's short history, lack of a security policy and security-scanning tooling, one workflow with top-level write permissions, and low repository popularity; these are transparency and hardening gaps rather than evidence of abandonment.
88%
Total Score
100
100
83
80
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version 14.3.*@dev | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
typo3/cms-frontend Version 14.3.*@dev | — | — |
symfony/expression-language Version ^7.4.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.