PHPackages                             lochmueller/securitytxt - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Security](/categories/security)
4. /
5. lochmueller/securitytxt

ActiveTypo3-cms-extension[Security](/categories/security)

lochmueller/securitytxt
=======================

security.txt integration

0.1.0(9mo ago)35[1 issues](https://github.com/lochmueller/securitytxt/issues)GPL-2.0-or-laterPHPPHP ^8.3

Since Aug 19Pushed 9mo agoCompare

[ Source](https://github.com/lochmueller/securitytxt)[ Packagist](https://packagist.org/packages/lochmueller/securitytxt)[ Fund](https://paypal.me/lochmueller)[ GitHub Sponsors](https://github.com/lochmueller)[ RSS](/packages/lochmueller-securitytxt/feed)WikiDiscussions main Synced 1mo ago

READMEChangelogDependencies (2)Versions (2)Used By (0)

TYPO3 Extension: security.txt Integration
=========================================

[](#typo3-extension-securitytxt-integration)

This TYPO3 extension provides support for the [security.txt standard](https://securitytxt.org/), which defines a standard way for security researchers to report security vulnerabilities.

By adding a `/.well-known/security.txt` file to your TYPO3 installation, this extension helps your project communicate a clear and standardized security contact policy.

Features
--------

[](#features)

- Automatically serves a `/.well-known/security.txt` file.
- Support multi tenant installations.
- Fully compliant with the [RFC 9116 specification](https://www.rfc-editor.org/rfc/rfc9116).
- Easy configuration through TYPO3 backend.
- Supports multiple contact methods (email, URL, etc.).

Installation
------------

[](#installation)

Install the extension via [Composer](https://getcomposer.org/):

```
composer require lochmueller/securitytxt
```

More information
----------------

[](#more-information)

-
-
-

Open @todo
----------

[](#open-todo)

- Add to

###  Health Score

28

—

LowBetter than 54% of packages

Maintenance52

Moderate activity, may be stable

Popularity7

Limited adoption so far

Community6

Small or concentrated contributor base

Maturity40

Maturing project, gaining track record

 Bus Factor1

Top contributor holds 100% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Unknown

Total

1

Last Release

272d ago

### Community

Maintainers

![](https://www.gravatar.com/avatar/11603a6f53d94137ce97cc4510dae54aaf652b5beda5eb932f390714dcb94595?d=identicon)[lochmueller](/maintainers/lochmueller)

---

Top Contributors

[![lochmueller](https://avatars.githubusercontent.com/u/3907126?v=4)](https://github.com/lochmueller "lochmueller (4 commits)")

###  Code Quality

Code StylePHP CS Fixer

### Embed Badge

![Health badge](/badges/lochmueller-securitytxt/health.svg)

```
[![Health](https://phpackages.com/badges/lochmueller-securitytxt/health.svg)](https://phpackages.com/packages/lochmueller-securitytxt)
```

###  Alternatives

[leuchtfeuer/secure-downloads

"Secure Download": Apply TYPO3 access rights to ALL file assets (PDFs, TGZs or JPGs etc. - configurable) - protect them from direct access.

22234.7k1](/packages/leuchtfeuer-secure-downloads)[derhansen/form_crshield

Challenge/response spambot protection for TYPO3 ext:form - Adds a hidden input field containing a challenge string to forms. Client must execute included JavaScript to calculate the expected response.

20205.1k6](/packages/derhansen-form-crshield)[causal/fal-protect

Protect everything within /fileadmin/ based on associated folder and file restrictions (visibility, user groups and dates of publication).

1269.5k](/packages/causal-fal-protect)[spooner-web/be_secure_pw

You can set password conventions to force secure passwords for BE users.

10461.3k](/packages/spooner-web-be-secure-pw)[georgringer/noopener

Add rel="noopener noreferrer" to all external links

1535.1k](/packages/georgringer-noopener)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
