Documentation, licensing, and repository ownership are clear, with a release note for this version and security reporting guidance. Maintenance has gone quiet for about one year, while the workflows use unpinned actions and contain high-confidence audit findings that merit review.
62%
Total Score
50
94
67
The repository recorded 0 commits and 0 active maintainers in the last 3 months, and the latest push was about one year ago. This is a meaningful abandonment risk for a framework integration.
The package runs a post-autoload-dump lifecycle script during installation. This adds some install-time complexity, but the provided signal does not show that the script is unsafe or unusually broad.
The package has had 8 releases since March 2023, but only 1 release in the last 12 months and the latest release was about one year ago. This indicates slowing maintenance rather than abandonment by itself.
There are 3 open issues and 2 open pull requests, but none were created or merged in the last month. The open work with no recent movement reinforces the maintenance concern.
All 3 workflows were analyzed, but all 6 action references are unpinned, and the audit reports high-confidence bot-condition and template-injection findings. The pull_request_target workflow has no untrusted checkout or script-injection count, so these findings warrant workflow review rather than proving a severe release risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^11.5 || ^12.4 || ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.