Only one contributor made the sole recent commit, and the repository has no security policy or scanning. Releases are regular and the repository is active, but workflow dependencies are all unpinned.
67%
Total Score
67
100
50
One contributor made 100% of the recent commits. Organization backing provides some handoff capacity, but no second active contributor is shown.
Only 1 commit was recorded in the last 3 months, indicating limited recent maintenance activity despite the regular release history.
The repository has no security policy and no documented security-scanning tooling was collected, leaving disclosure and security-maintenance practices unclear.
All 11 analyzed action references are unpinned, and one workflow has a low-confidence cache-poisoning finding; the audit also reports top-level write permissions in one workflow. No untrusted checkout or script-injection path was found, limiting the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
typo3/cms-backend Version ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.