It includes clear documentation, tests, and release notes. Organization ownership helps offset the single-contributor repository activity, but no security policy leaves less guidance for reporting problems.
72%
Total Score
75
100
94
88
One contributor made all 2 commits in the last 3 months, creating a concentrated maintenance path. Organization ownership provides some ability to hand work off, but no second active contributor is shown.
Only 2 commits were made in the last 3 months, indicating modest recent source activity despite 10 registry releases in the last year.
Composer build tooling is present, but no security-scanning tool was detected. This is a minor transparency and maintenance gap rather than a severe concern.
The repository has no security policy, leaving no documented process for reporting vulnerabilities or setting response expectations.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-47408 fixpunkt/fp-newsletter is vulnerable to Improper Authentication in versions 2.2.0 - 3.2.6, 2.0.0 - 2.1.2 and 0.0.0 - 1.1.1. | 0.0.0 - 1.1.12.0.0 - 2.1.22.2.0 - 3.2.6 | Critical |
CVE-2022-47410 fixpunkt/fp-newsletter is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 1.1.1, 1.2.0 - 2.1.2 and 3.0.0 - 3.2.6. | 0.0.0 - 1.1.11.2.0 - 2.1.23.0.0 - 3.2.6 | High |
CVE-2022-47411 fixpunkt/fp-newsletter is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 1.1.1, 1.2.0 - 2.1.2 and 3.0.0 - 3.2.6. | 0.0.0 - 1.1.11.2.0 - 2.1.23.0.0 - 3.2.6 | High |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.