Clear documentation, repository tests, and a recent release provide useful support. The license mismatch, missing security policy, and entirely unpinned workflow actions reduce confidence despite read-only job permissions.
67%
Total Score
75
100
86
83
A GPL-2.0-or-later manifest declaration and license files are present, but the artifact license file was detected as GPL-3.0. The mismatch creates a real licensing ambiguity for consumers.
The repository recorded zero commits and zero active maintainers in the last three months. This is concerning for maintenance capacity, although the recent release shows some publication activity.
Composer build tooling is present, but no security scanning tools were detected. That is a hygiene gap rather than evidence of abandonment.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it does not by itself indicate that the package is unsafe to depend on.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous sinks or audit findings. However, all 9 action references are unpinned, leaving workflow dependencies exposed to upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.