The package has a clear license, useful documentation, and a repository that matches the package and organization behind it. Its simple dependency set and recent stable release help, but limited recent development and workflow pinning reduce confidence.
70%
Total Score
75
100
93
50
No commits and no active maintainers were recorded during the last three months. The release on the same date provides some compensation, but the recent development gap still lowers confidence in ongoing maintenance.
The repository uses Composer, but no security-scanning tool was detected. For a small PHP extension this is a hygiene gap rather than evidence of abandonment.
The repository has no security policy. This reduces disclosure transparency, although it does not by itself show that the release is unsafe to depend on.
The sole workflow was fully analyzed and has a high-confidence template-injection finding; that is a workflow hygiene concern, though no untrusted checkout or script-injection trigger was reported. Both action references are unpinned, making the release workflow more exposed to dependency changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.0 || ^14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.