Package Health

in2code/lux

This is a mature, actively released TYPO3 extension with a substantial codebase, a matching organizational repository, a clear GPL-2.0-or-later license, no deprecation, no install-time lifecycle scripts, and 31 releases in the last 12 months. Recent repository commits show two active maintainers and the repository is not archived, although commit ownership is highly concentrated in one contributor, issue and pull-request activity has been quiet for a month, and the repository lacks a security policy, security scanning, and explicit workflow token permissions. These are meaningful governance and continuity cautions, but the strong release cadence, recent source updates, repository alignment, and organizational backing make the package generally reasonable to depend on with normal maintenance and security review.

Latest 44.3.0PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

One contributor made 21 of 22 recent commits, a 95.5% share, creating a concentrated continuity risk. A second contributor remains active and the repository is organization-owned, which provides some handoff capacity but does not eliminate the concentration concern.

Repo issue activitycaution

There are 7 open issues and 2 open pull requests, but no new or closed issues and no new or merged pull requests in the last month. The lack of recent issue-flow activity is a maintenance-transparency caution, though it is outweighed by recent commits and releases.

Repo toolingcaution

The repository uses make and Composer build tooling, supporting reproducible project operations, but no security scanning tools were detected. The missing scanning is a governance gap rather than evidence of abandonment.

Security policycaution

No repository security policy was found. This reduces transparency about vulnerability reporting and response procedures, although it does not by itself indicate unsafe code.

Token permissionscaution

Neither of the two analyzed workflows declares top-level token permissions. Although no workflow requests explicit top-level write access, the absence of least-privilege declarations leaves workflow permissions less constrained than ideal.

Vulnerabilities

TitleVersionsSeverity
CVE-2022-35628
in2code/lux is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 18.0.0 - 24.0.2 and 0.0.0 - 17.6.1.
0.0.0 - 17.6.118.0.0 - 24.0.2
Critical

Package versions

Maintainers

Florian Froidevaux
Alex Kellner

Direct Dependencies

DependencyLast ReleaseScore
in2code/bing
Version ^1.1
typo3/cms-core
Version ^13.4 || ^14.0
buzz/which-browser-parser
Version ^2.1
symfony/expression-language
Version >=4.0

Weekly Downloads

Info

Last Published
18 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform