The package has clear licensing, release notes, an identified source repository, and active organization backing. Its small release history, single recent contributor, and high-confidence workflow warnings warrant extra review before adoption.
64%
Total Score
88
100
86
75
The package has only 4 releases across 814 days, with 2 releases in the last 12 months and a median interval of about 252 days. The recent release shows ongoing work, but the overall cadence is sparse.
There were 2 commits in the last 3 months, so maintenance is active but not intensive.
The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent.
Version 0.3.1 is not a stable-major release, although it is not a prerelease and recent releases contain no prerelease versions.
All 3 workflows were analyzed, all 10 action references are pinned, and no untrusted checkout or script-injection sink was found. However, the release workflow has two high-confidence template-injection findings, which is a material workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ~13.4.0 || ~14.3.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
typo3/cms-extbase Version ~13.4.0 || ~14.3.0 | — | — |
psr/event-dispatcher Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.