Its stable release history, clear README, matching repository, and explicit license support adoption. Workflow references are unpinned, and the repository lacks security scanning and a security policy, leaving maintenance and build hygiene concerns.
60%
Total Score
67
100
93
67
There were no commits and no active maintainers in the last three months, which is a concrete sign that maintenance may be slowing.
No issues or pull requests were opened or closed in the last month, with one issue and one pull request still open; this provides little evidence of active community maintenance.
Composer is used for builds, but no security scanning tools were detected, leaving a modest gap in repository hygiene.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
The single workflow was fully analyzed, but both action references are unpinned and it contains a high-confidence template-injection finding; without an untrusted trigger or checkout this is workflow hygiene risk rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-backend Version ^10.4 || ^11.0 || ^12.4 || ^13.0 || ^14.0 | — | — |
typo3/cms-fluid-styled-content Version ^10.4 || ^11.0 || ^12.4 || ^13.0 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.