The repository is intact and the package has a useful README plus release notes for this version. Activity has stopped for over two years, and its publishing workflow has unpinned actions plus a high-confidence template-injection finding.
20%
Total Score
75
67
67
Packagist marks the package abandoned at package scope and points developers to b13/bolt as its replacement. This is a severe adoption risk even though the linked repository remains available.
The last registry release was over two years ago, with no releases in the preceding 12 months. Its earlier history was established, but the current release cadence indicates abandonment risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long gap since the latest release. This materially lowers confidence in ongoing maintenance.
The linked repository has no security policy, leaving vulnerability-reporting and response procedures undocumented. This is a transparency gap, although it is secondary to the package's abandoned status.
All five analyzed action references are unpinned, and the publishing workflow has a high-confidence template-injection finding. The audit was complete, and the finding affects release-workflow hygiene even without an untrusted checkout or script-injection trigger.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^10.4 || ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.