The project has a long release history, recent publishing, organization backing, and repository activity. This release is a release candidate, while recent commits are limited to one contributor and all 13 workflow actions are unpinned.
68%
Total Score
80
100
93
75
One contributor made all commits in the last three months, giving the recent activity a 100% concentration; organization backing provides some handoff capacity but does not remove the near-term concentration risk.
Only one commit was recorded in the last three months, and only one maintainer was active; this is a meaningful sign of recently thin maintenance.
The repository has no security policy, leaving vulnerability reporting guidance less transparent for consumers of this integration package.
v5.0.0-rc2 is a prerelease, so its API and behavior may still change; the recent prerelease share is only 10%, which partly limits the concern.
All three workflows were analyzed without high-confidence findings or untrusted checkout and script-injection patterns. However, all 13 action references are unpinned, which weakens build reproducibility; the absence of top-level permissions is not a concern by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.0 | — | — |
typo3/cms-install Version ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.