The repository is active and the release is documented, licensed, and backed by an organization. Recent work is very limited and comes from one contributor, while the project has no security policy and its sole workflow dependency is unpinned.
72%
Total Score
67
100
93
67
One contributor made all commits in the last three months. Organization ownership provides some handoff capacity, but current activity remains concentrated.
Only one commit was recorded in the last three months, indicating very light recent development despite the recent release history.
Composer build tooling is present, but no security scanning tools were detected, leaving a repository hygiene gap.
No repository security policy was found, reducing transparency about how vulnerabilities should be reported and handled.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but its one action use is unpinned, so the workflow is less reproducible than it could be.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4.8 | — | — |
jweiland/glossary2 Version >=7.0.0 | — | — |
jweiland/yellowpages2 Version >=8.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.