Security scanning is not configured and the repository has no security policy. Its build workflows are complete and avoid untrusted checkouts or script injection, while the package remains actively developed.
82%
Total Score
100
100
94
67
Composer build tooling is present, but no security-scanning tools were detected, leaving dependency and build-risk checks less visible.
The repository has no published security policy, so the process for reporting and handling vulnerabilities is not documented.
Both workflows were analyzed successfully with no untrusted checkouts, script injection, or high-confidence audit findings. However, all 7 action references are unpinned, a workflow reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
typo3/cms-backend Version ^13.4 || ^14.3 | — | — |
typo3/cms-frontend Version ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.