The package includes a license, documentation, repository tests, and a security policy. CI has no flagged audit findings, though some actions are unpinned and one workflow grants write access.
78%
Total Score
75
100
92
83
Three Composer install and update lifecycle scripts run during package operations, increasing execution complexity and supply-chain exposure even though such scripts can be legitimate for PHP packages.
The repository is owned by an individual user rather than an organization, so the highly concentrated recent commit activity provides limited evidence of maintenance handoff capacity.
One contributor made 66 of 68 recent commits, so maintenance is highly concentrated despite two additional active contributors; this raises continuity risk.
Composer and make provide build tooling, but no security-scanning tool was detected in the repository, leaving a modest transparency and hygiene gap.
Both workflows were analyzed without failed files or audit findings, and no untrusted checkout or script-injection risks were found. However, 3 of 6 action references are unpinned and one workflow grants top-level write permissions, creating moderate workflow hygiene risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-46721 evoweb/sf-register is vulnerable to Authorization Bypass Through User-Controlled Key in versions 14.0.0 - 14.0.2 and 0.0.0 - 13.2.4. | 0.0.0 - 13.2.414.0.0 - 14.0.2 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
doctrine/dbal Version ^4.1 | — | — |
typo3/cms-core Version ^14.3 || 14.*.*@dev || dev-main | — | — |
symfony/console Version ^7.1 | — | — |
typo3/cms-fluid Version ^14.3 || 14.*.*@dev || dev-main | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.