The package is clearly identified and documented, with a license and straightforward Composer dependencies. Its small project footprint, absent security policy, and unpinned workflow actions leave meaningful maintenance and build-trust gaps.
68%
Total Score
50
100
88
75
The package has existed since February 2016 and released version 7.2.0 in January 2026, but only one release appeared in the last 12 months across 10 releases, indicating a low cadence for a mature extension.
The repository recorded zero commits and zero active maintainers in the last three months. Although the latest release was recent, the lack of ongoing activity leaves maintenance capacity uncertain.
Composer is used for builds, but no security-scanning tooling is present. This is a modest transparency and assurance gap rather than evidence of an unsafe release.
The repository has no security policy. For a small extension this is a transparency gap, though it is less severe than an archived or deprecated project.
The workflow audit completed cleanly, uses read-only permissions, and found no high-confidence dangerous patterns. Both analyzed action references are unpinned, which weakens build reproducibility and action supply-chain integrity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4||^13.4||^14.0 | — | — |
typo3/cms-extbase Version ^12.4||^13.4||^14.0 | — | — |
typo3/cms-frontend Version ^12.4||^13.4||^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.