Healthy and suitable to depend on, with strong release activity, current source maintenance, licensing, tests, and security practices. The main caveat is that all recent commits came from one contributor, while one workflow lacks explicit permissions and another grants write access.
82%
Total Score
88
50
100
88
The 18 runtime dependencies reflect a substantial TYPO3, search, and metadata integration package; this adds maintenance surface but is consistent with its broad application role.
All 17 recent commits came from one contributor, creating a real continuity risk. Organization backing partly compensates because maintenance can potentially be handed off within the project.
One workflow omits top-level permissions and another grants top-level write access, leaving avoidable CI token exposure despite the absence of other dangerous workflow patterns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fluidtypo3/vhs Version ~6.0.5 | — | — |
typo3/cms-core Version ^9.5.0 | — | — |
galbar/jsonpath Version ^3.0 | — | — |
nategood/httpful Version ^0.3.2 | — | — |
symfony/workflow Version ~4.3.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.