Active releases and five recent contributors support ongoing maintenance. The missing security policy and fully unpinned actions add avoidable uncertainty.
68%
Total Score
100
100
50
The package runs pre-autoload-dump and pre-update-cmd scripts, which increase install and update complexity and deserve review when Composer changes are automated.
The repository has no security policy, leaving disclosure and response expectations undocumented for a package with backend and frontend runtime dependencies.
All 15 analyzed action references are unpinned, and a high-confidence template-injection finding appears in the publishing workflow. There are no untrusted checkouts or script-injection findings, so this is a meaningful hygiene concern rather than a standalone severe verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.4 | — | — |
symfony/finder Version ^7.4 | — | — |
typo3/cms-core Version ^14.3.7 | — | — |
symfony/console Version ^7.4 | — | — |
typo3/cms-fluid Version ^14.3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.