The project has recent commits and a current release, but all recent work comes from one contributor. The workflow uses broad write access and unpinned actions, adding maintenance and build-safety concerns.
45%
Total Score
75
50
50
Packagist marks the entire package as abandoned, with no distinct replacement identified; this is a major adoption and maintenance warning despite the recent release.
The package is mature but has only five releases since 2021, with one release in the last 12 months and a median interval of about 435 days, indicating a slow cadence.
One contributor made all six recent commits, leaving the project dependent on a single maintainer.
The repository has no security policy, leaving reporting and response expectations undocumented.
All three action references are unpinned and the release workflow has top-level write permissions; the high-confidence template-injection finding is a workflow hygiene concern, though no untrusted trigger or checkout sink was observed.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.