The source repository has tests, two active contributors, and organization backing. There is no security policy or automated security scanning, so transparency and preventive hygiene are weaker than the maintenance record.
88%
Total Score
100
94
50
A post-autoload-dump lifecycle script runs during installation, adding some execution surface, but this signal alone does not show harmful or unnecessary behavior.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanning is a hygiene gap, while the build setup supports reproducible project maintenance.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This lowers transparency but does not by itself indicate abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^5.1 | — | — |
typo3/cms-core Version ^14.3.0 | — | — |
auth0/auth0-php Version ^8.19.0 | — | — |
typo3/cms-fluid Version ^14.3.0 | — | — |
typo3/cms-backend Version ^14.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.