The package has a clear license, repository tests, security scanning, and a published security policy. Workflow findings warrant cleanup, while organization ownership provides some continuity despite concentrated development.
72%
Total Score
88
100
94
100
All 50 recent commits came from one contributor, creating a clear concentration risk. Organization ownership provides some ability to hand maintenance off, but no second active contributor is shown.
Version 1.0.0-alpha.13 is still a prerelease, and 60% of recent releases are prereleases. The stable major version context is reassuring, but consumers should expect API or behavior changes.
All three workflows were analyzed, all 23 action references are pinned, and no untrusted checkouts or script-injection sinks were found. High-confidence template-injection findings in the release workflow are a workflow hygiene concern; the low-confidence cache-poisoning finding is not independently weighty, and the absence of a top-level permissions block is acceptable here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/config Version ^7.2 || ^8.0 | — | — |
symfony/finder Version ^7.2 || ^8.0 | — | — |
typo3/cms-core Version ~13.4.11 || ~14.3.0 | — | — |
typo3/cms-fluid Version ~13.4.11 || ~14.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.