This is a healthy, established release with a clear GPL-2.0+ license, substantial README and test coverage, a complete-looking 39-file package tree, stable non-prerelease versioning, and a repository that is active, correctly associated with the package, and backed by an organization. The package has maintained a steady release cadence since 2021 and is not deprecated or archived. The main concerns are that recent repository work is concentrated in one contributor, the repository has no security policy or configured security-scanning tool, and its workflow does not declare top-level token permissions; these are meaningful hygiene and continuity gaps, but they do not outweigh the release and project evidence.
82%
Total Score
80
100
94
80
All 2 recent commits came from one contributor, creating continuity risk. The organization ownership provides some ability to hand maintenance off, but no second recent contributor is shown.
The repository had 2 commits in the last 3 months, showing recent activity, although the volume is modest.
Composer build tooling is present, but no security-scanning tool is configured; the missing scanner is a security-process gap rather than evidence of package abandonment.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
The only workflow lacks top-level permissions declarations. No write permissions were observed, but explicit least-privilege configuration is absent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^11.5 || ^12.4 || ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.