Usable, but maintenance signals have gone quiet: no releases in the last 12 months and no recent commits detected. Packaging transparency is decent (README present, license declared), yet CI hygiene is weaker with unpinned GitHub Action uses and no security policy.
58%
Total Score
50
83
50
The last release is older (latest on 2024-11-17) with 0 releases in the last 12 months. That suggests slower/paused upkeep, which matters for dependency reliability.
Repository commit activity is currently at 0 commits in the last 3 months and 0 active maintainers in that window. This compounds the recent-release gap as a maintenance-risk indicator.
No security policy is present (has_security_policy = false). For users, that’s a transparency gap that increases uncertainty about vulnerability reporting and handling.
The workflow audit found 2 unpinned action uses (unpinned_uses_count = uses_total = 2). Even without other workflow-level findings, this lowers CI supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^11.5 || ^12.4 || ^13.0 || dev-main | — | — |
typo3/cms-fluid Version ^11.5 || ^12.4 || ^13.0 || dev-main | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.