It has a clear README, release notes for this version, repository tests, and a recent release. The license mismatch and missing security scanning add smaller transparency concerns.
67%
Total Score
50
100
88
75
The manifest declares MIT, but the artifact license file is detected as GPL-2.0; although a license file exists, the mismatch creates uncertainty about the terms consumers receive.
The repository recorded zero commits and zero active maintainers in the last 3 months, a concrete sign that maintenance may have paused after the recent release.
Composer build tooling is present, but no security scanning tools were detected; this is a modest supply-chain hygiene gap, not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All 13 analyzed action references are unpinned, which weakens build reproducibility and update control. The pull_request_target workflow has no untrusted checkout or script-injection finding, and the absence of top-level permissions is not a problem by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.2 | — | — |
blueways/bw-jsoneditor Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.