Recent releases, tests, documentation, and release notes show a functioning project with clear consumer support. The small contributor base, absent security scanning, and unpinned workflow actions warrant extra operational caution.
68%
Total Score
88
100
94
67
One contributor made 20 of 21 recent commits, so maintenance is highly concentrated despite a second active contributor and organization backing.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and assurance gap.
The repository has no security policy, so vulnerability-reporting and response expectations are not documented.
All four workflows were analyzed without dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all four action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version >=12.4.0 <=14.9.99 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.