A single publisher and no security policy limit resilience if the maintainer steps away. The license, release notes, tests, documentation, and non-archived repository provide useful adoption support.
67%
Total Score
50
92
50
Only one registry account has publishing access, leaving a thin release-publishing base. The linked repository shows an identifiable individual owner, but that does not provide the resilience of a broader maintainer team.
The package has existed since 2018, but only one release appeared in the last 12 months and releases are typically about eight months apart. The recent v3.4.0 release provides some evidence of continued maintenance, but the cadence is slow.
There were no commits and no active maintainers in the last three months. This is a meaningful sign of slowed maintenance, although the recent release and repository push provide partial compensation.
The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, with no provided compensating security process.
Both workflows were analyzed successfully with no untrusted checkouts, script injection, or high-confidence audit findings. However, all seven referenced actions are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 || ^14.0 | — | — |
typo3/cms-fluid Version ^12.4 || ^13.4 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.