Fetch an RSS / Atom Feed and display its content on the Frontend.
66%
Total Score
67
100
100
67
The repository is owned by an individual rather than an organization, so there is no visible organizational handoff capacity to offset the concentrated contributor activity. Recent commits and releases provide some compensation.
All 9 commits in the last 3 months came from one contributor, giving the project a single-person maintenance dependency. The active repository and recent releases compensate partly, but they do not remove the continuity risk.
No repository security policy was found. For a package that processes external RSS or Atom content, the absence reduces vulnerability-reporting transparency, though it is not evidence of a vulnerability by itself.
All 3 workflows were analyzed successfully, but all 14 action references are unpinned. The audit also found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow and one workflow with top-level write permissions; the pull_request_target trigger has no untrusted checkout or script-injection sink.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.