The repository was pushed about 21 months ago, but the package has had no release since May 2022 and no commits in the last three months. The workflow has high-confidence template-injection and fully unpinned actions, while its license, documentation, and repository linkage are solid.
58%
Total Score
50
88
67
Only two releases were published, both in May 2022, with no release in roughly four years and none in the last 12 months. A repository push in January 2025 provides some compensating evidence of project activity, but the published package is stale.
There were no commits and no active maintainers in the last three months. The January 2025 push partly offsets this, but current maintenance activity remains thin.
Composer is used for builds, but no security-scanning tooling is configured, leaving a modest transparency and maintenance gap.
The repository has no published security policy, making vulnerability reporting and response expectations less clear.
The sole workflow has a high-confidence template-injection finding and both action references are unpinned. No untrusted checkout or dangerous trigger was observed, so this is a hygiene concern rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^9.5 || ^10.4 || ^11.5 | — | — |
typo3/cms-rte-ckeditor Version ^9.5 || ^10.4 || ^11.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.