Enable external youtube and vimeo videos only on click for TYPO3
64%
Total Score
75
89
50
There were no commits and no active maintainers in the last three months, which is a meaningful maintenance concern despite the repository having been pushed recently and the package having a recent release.
The repository has only 2 stars and 5 forks, so public adoption appears limited. This is supporting caution rather than a decisive health problem because the project is organization-backed and maintained.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, making the process for reporting and handling vulnerabilities unclear.
The single workflow was fully analyzed and has no untrusted checkout or script-injection trigger, but both action references are unpinned and the audit found a high-confidence template-injection issue. These are CI hygiene and supply-chain concerns, not evidence that the package itself is malicious.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14 | — | — |
typo3/cms-fluid Version ^13.4 || ^14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.