Workflow protections are uneven, with all 31 action references unpinned and three workflows granting top-level write access. A security policy is absent, though regular releases, a maintained repository, tests, licensing, and organization backing offset these concerns.
72%
Total Score
75
100
100
67
There were zero commits and zero active maintainers in the last three months, which is a meaningful maintenance warning despite the recent push and active release history.
No issues or pull requests were opened, closed, or merged in the last month, suggesting limited current project activity; the existing open work prevents this from proving abandonment.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package used within TYPO3 projects.
All seven workflows were analyzed with no reported audit findings, but all 31 action references are unpinned and three workflows grant top-level write access; the single pull_request_target trigger has no untrusted checkout or script-injection sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
nikic/php-parser Version ^5.1.0 | — | — |
typo3/cms-backend Version ^13.4 | — | — |
doctrine/inflector Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.