This release appears healthy and suitable to depend on: it is a stable major version with a multi-year history, regular recent releases, an active and non-archived source repository, current commit activity from two maintainers, repository-backed tests, and a clear package-specific repository match. The declared GPL-2.0-or-later license, absence of install lifecycle scripts, modest runtime dependency footprint, and clean workflow risk profile further support adoption. The main reservations are the absence of a repository security policy and explicit top-level workflow token permissions, plus limited repository popularity; these are hygiene gaps rather than evidence of abandonment, especially given the organization-backed project and recent release and commit activity.
88%
Total Score
100
100
94
80
Composer build tooling is present, but no security scanning tools were detected; this is a modest repository hygiene gap, not evidence of unsafe or abandoned maintenance.
No security policy was found in the repository, reducing transparency for vulnerability reporting and response procedures.
The only workflow lacks top-level token permissions; although no write permissions were detected, explicitly declaring least-privilege permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-form Version ^14.2 || ^14.3.x-dev | — | — |
typo3/cms-install Version ^14.2 || ^14.3.x-dev | — | — |
typo3/cms-frontend Version ^14.2 || ^14.3.x-dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.