Healthy and actively maintained, with clear documentation and recent releases. The main caveat is that all recent commits come from one contributor, while repository workflow permissions and the lack of a security policy reduce transparency somewhat.
82%
Total Score
75
100
67
One contributor made 100% of the 8 commits in the last 3 months. The organization-owned repository provides some handoff capacity, but no second recent contributor is shown.
There were 8 commits in the last 3 months, but all were produced by one active maintainer. This demonstrates recent work while leaving limited short-term contributor redundancy.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear.
One workflow has no top-level token permissions and another declares top-level write permissions, which is weaker least-privilege hygiene than a consistently restrictive setup.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
typo3/cms-core Version ~14.3.7 | — | — |
symfony/console Version ^7.4 || ^8.0 | — | — |
typo3/cms-fluid Version ~14.3.7 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.