The focused runtime dependency and straightforward configuration guidance make integration simple. Organization backing and two active contributors support continuity, while unpinned workflow actions and limited security process leave modest hygiene gaps.
78%
Total Score
100
100
86
83
The artifact includes a LICENSE file and the repository also has one, but the detected GPL-2.0 text is narrower than the declared GPL-2.0-or-later license and warrants clarification.
Only four releases over about 2 years and 10 months, with a median interval of about 15 months, indicate a slow cadence; two releases in the last 12 months and recent commits partly compensate.
The repository has no security policy, leaving vulnerability-reporting guidance undocumented and creating a modest transparency gap.
The sole workflow was fully analyzed with no injection or high-severity findings, but all three action references are unpinned; the absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.