The package includes automated tests, release notes for this version, and an organization-backed repository. Maintenance is concentrated in one recent contributor, while the workflow uses a floating container image; pin the image and keep this version under review.
68%
Total Score
67
100
50
One contributor made all recent commits, concentrating near-term maintenance knowledge and creating a real handoff risk, although organization ownership provides some compensation.
Only two commits were recorded in the last 3 months, which shows some activity but a thin maintenance pace.
The repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented.
The single workflow was fully analyzed and uses read-only permissions, but its high-confidence finding identifies a container image tagged latest, which makes builds less reproducible.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-redirects Version ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.