A clear license, useful documentation, repository tests, and regular releases provide strong adoption support. Organization backing and recent activity reduce abandonment concerns despite limited individual participation.
82%
Total Score
88
94
75
Two contributors are active, but one made 27 of 28 recent commits. That concentration leaves a meaningful continuity risk, partly offset by organization backing.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and assurance gap, not evidence of unsafe code.
The repository has no security policy. That weakens the documented process for reporting and handling vulnerabilities, though active maintenance and organization ownership provide some compensation.
The sole workflow was fully analyzed with no audit findings or untrusted-trigger sinks, but all five action references are unpinned. Unpinned actions leave CI exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.0 | — | — |
typo3/cms-form Version ^14.0 | — | — |
typo3/cms-fluid Version ^14.0 | — | — |
typo3/cms-backend Version ^14.0 | — | — |
typo3/cms-extbase Version ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.