Bootstrap Package delivers a full configured frontend theme for TYPO3, based on the Bootstrap CSS Framework.
84%
Total Score
75
100
94
80
The repository is owned by an individual user rather than an organization, so there is no organizational succession signal; however, the observed multi-contributor activity provides meaningful compensation.
The top contributor made about 66% of the 38 recent commits, creating some concentration risk, although six additional contributors were active and the second contributor supplied about 21%.
Composer build tooling is present, but no security-scanning tools were detected; this is a transparency and defense-in-depth gap rather than evidence of unsafe behavior.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability-reporting and response expectations less transparent.
Both workflows lack top-level permissions declarations. No workflow declares top-level write access, but explicit least-privilege permissions are still missing.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-21365 bk2k/bootstrap-package is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 7.1.0 - 7.1.2, 8.0.0 - 8.0.8, 9.0.0 - 9.0.4, 9.1.0 - 9.1.3, 10.0.0 - 10.0.10 and 11.0.0 - 11.0.3. | 7.1.0 - 7.1.28.0.0 - 8.0.89.0.0 - 9.0.4 +3 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-seo Version ^13.4 || ^14.3 | — | — |
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
scssphp/scssphp Version ^1.13 | — | — |
typo3/cms-fluid Version ^13.4 || ^14.3 | — | — |
typo3/cms-backend Version ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.