The project has recent releases and a clear, complete package tree. Maintenance depends on one contributor, while the release workflow has high-confidence template-injection findings and all five actions are unpinned.
62%
Total Score
67
100
86
75
A license file is present, but the manifest declares GPL-2.0-or-later while the artifact license text was detected as GPL-3.0. The mismatch warrants checking the intended licensing before adoption.
The repository is owned by an individual rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
All 6 recent commits came from one contributor, giving the project a bus factor of one. The active repository offsets abandonment concerns partially, but there is no demonstrated maintenance backup.
Composer build tooling is present, but no security scanning tool was detected. This is a maintenance and transparency gap rather than evidence of an unsafe release by itself.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. That lowers transparency for a package used in web applications.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.