The package is clearly documented, licensed, stable, and has a recent release. Maintenance is concentrated in one person with no commits in three months, while the release workflow has high-confidence template-injection findings and uses two unpinned actions.
60%
Total Score
50
100
89
75
The complete audit found two high-confidence template-injection findings in the release workflow and one script-injection count; both actions are also unpinned. The workflow has no top-level permissions block, which is acceptable alone, but the injection findings make release automation a material supply-chain hygiene concern.
Only one account has registry publish access. The project is user-owned rather than organization-backed, so this represents a real single-maintainer continuity risk.
The registry namespace and repository are owned by the same individual account, confirming a consistent project owner but no organizational backing to compensate for the thin maintainer base.
The repository recorded zero commits and zero active maintainers in the last three months. Although the recent push and release history provide some compensation, this still indicates weak current maintenance activity.
The repository has 4 stars, 0 forks, and 1 watcher. Low adoption is supporting evidence of a small project, but it is not by itself a dependency-health failure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version >=12.4.0,<=13.4.99 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.