Recent commits from two contributors and a documented release change show active maintenance. The workflows need tightening because all five actions are unpinned, while a high-confidence template-injection finding remains a hygiene concern. The project is backed by an organization and is not archived.
78%
Total Score
100
92
75
Composer build tooling is present, but no security scanning tools were detected. That is a modest transparency and hygiene gap, not evidence of abandonment.
The repository has no security policy, leaving vulnerability reporting expectations unclear. This lowers transparency but is not severe on its own.
All 5 analyzed action references are unpinned, creating avoidable build-reproducibility risk. The audit also found one high-confidence template-injection issue; with no untrusted checkout or script-injection trigger reported, this remains workflow hygiene rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-backend Version ^13.4 || ^14.3 | — | — |
typo3/cms-extbase Version ^13.4 || ^14.3 | — | — |
typo3/cms-install Version ^13.4 || ^14.3 | — | — |
typo3/cms-frontend Version ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.