This release appears suitable for adoption with moderate caution: it is actively maintained, non-deprecated, backed by an organization-owned repository, and has substantial repository tests, documentation, CI, and recent commit activity. The main concerns are that version 0.9.0 is not yet a stable major release, activity is highly concentrated in one contributor, the repository lacks a security policy and security-scanning tooling, and one release workflow does not declare top-level token permissions. The unusually frequent release cadence also suggests an evolving project, though it provides evidence of active maintenance rather than abandonment.
78%
Total Score
88
100
88
80
Two contributors were active, but the leading contributor made about 95% of recent commits. The organization-owned repository provides some ability to hand off maintenance, but the observed activity remains highly concentrated.
The repository uses Composer and contains build and test configuration, supporting reproducible project maintenance. It reports no security-scanning tools, leaving a security-hygiene gap.
The repository has no SECURITY.md or other detected security policy. For a package explicitly intended to protect web applications, this is a meaningful vulnerability-reporting and transparency gap.
One of two workflows, release.yml, lacks top-level token permissions, while the other declares read-only permissions and neither declares top-level write access. The missing declaration weakens least-privilege assurance for the release workflow.
Version 0.9.0 is not a stable major release, so API and behavior compatibility may still change. It is not marked as a prerelease, which partially offsets the maturity concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 || ^14.0 | — | — |
flowd/phirewall Version ^0.10.0 | — | — |
typo3/cms-backend Version ^12.4 || ^13.4 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.