It has a clear license, release notes, README, security policy, and recent activity from three contributors. Pin the five GitHub Actions and fix the publish workflow's template expansion before relying on automated releases.
68%
Total Score
100
100
94
83
The project uses Composer build tooling, but no security scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence of abandonment.
Both workflows were analyzed successfully and have no untrusted checkouts or script-injection findings, but all 5 action references are unpinned. The publish workflow also has a high-confidence template-injection finding, which creates a meaningful release-automation hygiene risk even without a dangerous trigger.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-backend Version ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.