Its README, tests, changelog, and release notes make the extension straightforward to evaluate. Organization backing and regular releases help, though the small active contributor base and unpinned CI images leave maintenance and build-integrity caveats.
70%
Total Score
75
100
50
All 2 commits in the last 3 months came from one contributor, giving the project a concentrated active contributor base. Organization backing partly compensates, but handoff capacity is still limited.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures unclear. This is a transparency gap, not evidence that the package is unsafe.
The workflow audit completed fully and found no untrusted checkouts or script injection, but all 6 action references are unpinned and two high-confidence unpinned-image findings remain. The low-confidence cache findings are hygiene concerns only.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 || ^14.0 | — | — |
typo3/cms-backend Version ^12.4 || ^13.4 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.