Version 7.0.0 appears to be a healthy, actively maintained release from a long-lived package with 22 releases since 2017, 12 releases in the last 12 months, a stable major version, an active non-archived organization-owned repository, and recent activity from two maintainers. The repository and package clearly correspond, the artifact is licensed and documented, dependencies are minimal, and the CI workflow shows no analyzed dangerous patterns. The main reservations are concentrated commit activity, no repository security policy or dedicated security scanning, and workflow token permissions that are not explicitly constrained; these are meaningful hygiene concerns but do not outweigh the strong release and maintenance evidence.
86%
Total Score
90
100
89
80
Two contributors were active, but one authored 6 of 7 commits, an 86% share. The organization-owned repository and continued second-contributor activity partly mitigate this concentration, but it remains a maintenance-continuity caution.
The repository has seven forks and three watchers but no stars. This is limited supporting visibility, though low popularity is not by itself a health failure for a specialized extension.
Composer build tooling is present, but no security-scanning tool was detected. For a maintained extension this is a genuine security-process gap, though it is not evidence of malicious behavior.
No repository security policy was found, which reduces transparency about vulnerability reporting and response procedures.
The sole workflow has no top-level token permissions declaration. Although no top-level write permissions were detected, the absence of an explicit restrictive policy is a workflow-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.