Usable with caveats: the package is mature, actively released, unarchived, and clearly backed by its matching repository. However, recent commit activity is absent, testing and security coverage are thin, and the install script and workflow permissions deserve review.
67%
Total Score
67
100
83
70
A post-install-cmd script runs during installation, adding execution behavior that should be reviewed before adoption. No provided signal shows that this script is unsafe, so this is a review concern rather than a severe risk.
The artifact includes a substantial README and the repository uses GitHub Releases, but neither the artifact nor repository contains tests or a changelog. The missing tests reduce confidence in regression protection for this functional extension.
The registry namespace and repository are associated with the same individual owner, and the repository is not organizationally backed. The small two-account registry maintainer base therefore offers limited redundancy.
There were zero commits and zero active maintainers in the last three months. The very recent release and repository push provide some compensation, but the lack of sustained commit activity is a meaningful maintenance concern.
The repository has 10 stars, 38 forks, and 7 watchers, indicating a small user and contributor footprint. Low popularity is supporting caution rather than evidence that the package is unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12 || ^13 || ^14 | — | — |
gridelementsteam/gridelements Version ^12 || ^13 || dev-ea_14-0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.