The package includes a usable README, focused runtime dependencies, and an explicit GPL-2.0-or-later license. Its post-autoload-dump hook adds installation complexity, and the source repository could not be found for maintenance or provenance checks.
32%
Total Score
100
75
50
The latest release was in October 2021, with no releases in the last 12 months despite about five years of package age. This is strong evidence of abandonment risk, although the 15-release history shows the project was previously active.
The package runs a post-autoload-dump lifecycle script during installation. This adds operational and supply-chain exposure beyond a passive library, so it warrants caution even without evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^9.5.17 || ^10.4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.