The repository is active, documented, licensed, and has three recent contributors. Workflow references are all unpinned, with one high-confidence template-injection warning; the package also runs an install-time script.
58%
Total Score
83
86
50
Packagist marks the entire package abandoned, although the replacement points to the same package. This is a meaningful maintenance and adoption warning, but it is partly offset by recent releases and repository activity.
A post-autoload-dump install-time script runs during Composer setup. This adds execution complexity for consumers, but the signal provides no evidence that the script is unsafe.
The repository is owned by an individual account rather than an organization account, so the package's two registry maintainers do not provide strong evidence of organizational handoff capacity.
All 12 workflows were analyzed without failures, but all 53 action references are unpinned. The audit also found a high-confidence template-injection warning and a low-confidence cache-poisoning warning; without dangerous triggers, these are workflow hygiene concerns rather than standalone severe risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
doctrine/dbal Version ^3.10 || ^4.3 | — | — |
typo3/cms-seo Version ^12.4 || ^13.4 | — | — |
typo3/cms-core Version ^12.4 || ^13.4 | — | — |
typo3/cms-info Version ^12.4 || ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.