The project has a clear license, tests, documentation, and recent releases. Ongoing work is concentrated in one contributor, with no security policy and unpinned workflow actions adding maintenance and supply-chain concerns.
68%
Total Score
67
100
94
50
One contributor made all commits in the last 3 months. Organization ownership offers some continuity, but current maintenance knowledge is still concentrated.
Only one commit was recorded in the last 3 months. The recent release offsets this somewhat, but source-level activity is currently thin.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities in a package that integrates with TYPO3 sites.
The single workflow was fully analyzed with no audit findings and no dangerous triggers, but both action references are unpinned. That weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-seo Version ^13.4.0 || ^14.3.0 | — | — |
typo3/cms-core Version ^13.4.0 || ^14.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.