The package is well documented, licensed, and tested, with a small dependency surface. Its workflows use read-only permissions, but all 11 actions are unpinned and one maintainer made all 12 recent commits.
68%
Total Score
67
100
89
83
The repository owner is an individual user rather than an organization, so the single-maintainer concentration is not visibly offset by organizational handoff capacity.
One contributor made all 12 commits in the last three months, leaving no demonstrated backup maintainer and increasing continuity risk if that contributor becomes unavailable.
The repository has one star, one fork, and one watcher. This is limited supporting evidence of community adoption, but popularity is not decisive for a small, actively maintained extension.
Composer build tooling is present, but no security scanning tools were detected. This is a maintenance and assurance gap, not evidence that the package is unsafe by itself.
The repository has no security policy, so vulnerability-reporting and response expectations are not documented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.