A clear README, tests, frequent releases, and an exact repository match improve day-to-day confidence. Licensing and release notes are also in place, but no security policy and one-person activity leave limited backup.
82%
Total Score
67
100
94
67
The repository owner is an individual account, not an organization, so the single-contributor maintenance pattern is not visibly backed by a broader team.
All recent commits came from one contributor, with a 100% top-contributor share. The repository owner is an individual rather than an organization, so there is little visible handoff capacity.
Composer build tooling is present, but no security-scanning tool was detected. That is a maintenance and transparency gap, though not evidence of an unsafe release by itself.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities.
All four workflows were analyzed successfully and no audit findings or untrusted checkout/script-injection sinks were reported. However, all 12 action references are unpinned, which weakens build reproducibility; the pull_request_target trigger has no identified dangerous sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.0 || ^13.0 || ^14.0 | — | — |
gregwar/captcha Version ^2.1 | — | — |
maikschneider/steganography Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.