The package has clear licensing, a substantial README, repository tests, and an organization-backed source project. Recent commit activity is absent, while all three workflow actions are unpinned and a high-confidence template-injection issue was found. It remains maintained enough to consider, but warrants caution around updates and automation.
68%
Total Score
75
100
94
67
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning, although the recent 2.0.1 release shows the project has not been abandoned outright.
Composer build tooling is present, but no security-scanning tool was detected. This is a hygiene gap rather than evidence that the release is unsafe by itself.
The repository has no security policy, leaving vulnerability-reporting expectations and response guidance unclear.
Both workflows were analyzed successfully, with no untrusted checkout or script-injection findings, but all 3 action references are unpinned. The high-confidence template-injection finding in publish.yml is a release-automation hygiene risk; template injection alone does not establish a severe dependency risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 || ^14.3 | — | — |
typo3/cms-frontend Version ^12.4 || ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.