Tests, a clear README, and organization backing provide useful maintenance context. The workflow configuration still needs careful review before adoption because its actions are unpinned and its release workflow contains a high-confidence finding.
58%
Total Score
75
100
86
50
The package has had no releases in the last 12 months, despite a latest release on September 19, 2025. This indicates slowed maintenance, though the project is less than three years old and has seven releases overall.
There were no commits and no active maintainers during the last three months. Combined with no releases in the last 12 months, this is meaningful evidence of currently inactive maintenance.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. The otherwise documented project and tests provide some compensation, but not a complete substitute.
All 11 analyzed action references are unpinned, which weakens build reproducibility. The release workflow also has a high-confidence template-injection finding; without a dangerous trigger or untrusted checkout reported here, this remains workflow hygiene rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.