The package is licensed, documented, and has a focused dependency set. Workflow references are unpinned, and no security policy or scanning tool is present, but these are manageable transparency and build-hygiene gaps.
84%
Total Score
80
100
88
67
Only one registry account has publish access, which creates some publishing continuity risk; the repository's active contributors provide partial compensation.
The package has existed since June 2017 with 15 releases, but only one release in the last 12 months and a median interval of about 139 days indicate a slower release cadence.
The top contributor made about 73% of recent commits, but two additional contributors were active during the same three-month period, reducing the concentration concern.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest source-maintenance hygiene gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12 || ^13 | — | — |
georgringer/news Version ^12.2 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.