The stable release history, organization backing, README, and Psalm checks provide useful support for ongoing use. One registry maintainer, no security policy, and limited recent development leave less evidence of durable support.
68%
Total Score
67
100
100
50
The package declares four Composer lifecycle scripts, which add install and update execution paths and modestly increase supply-chain exposure.
Only one registry account has publish access, which is a support and release-continuity concern; organization backing provides some compensation but does not remove the single-publisher dependency.
The repository recorded no commits and no active maintainers in the last three months. Recent release activity partly offsets this, but it leaves current maintenance capacity uncertain.
No repository security policy was found, reducing transparency about how vulnerabilities are reported and handled.
Both workflows were analyzed completely and have no untrusted checkout or script-injection findings, but the audit found a high-confidence unpinned container image and all three action references are unpinned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4||^13.4 | — | — |
apache-solr-for-typo3/solr Version ^12||^13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.