The package has a clear README, explicit GPL licensing, and organization backing. Its small scope and single runtime dependency limit complexity, but the lack of recent commits and unpinned workflow actions reduce confidence in ongoing upkeep.
63%
Total Score
75
100
90
50
The package has existed for about 6 years and has five releases, but only one release in the last 12 months with a median interval of about 503 days indicates a slow maintenance cadence.
No commits and no active maintainers were observed during the last 3 months, which is evidence of limited recent upkeep even though the repository is not archived.
The repository has no security policy, leaving the preferred process for reporting vulnerabilities undocumented.
The single workflow was fully analyzed with no dangerous sinks or audit findings, but both of its two action references are unpinned, leaving them exposed to upstream movement.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version >=10.3.0 <= 10.4.99 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.