The package includes tests, a changelog, a clear README, and release notes for this version. All six workflow actions are unpinned, and the repository has no security policy, so updates and incident handling deserve extra care.
78%
Total Score
83
83
75
The release includes a LICENCE file and declares GPL-2.0-or-later, so it is licensed. The detected GPL-2.0 text is narrower than the declaration and merits a small compatibility check.
The package and repository are owned by the same individual user rather than an organization. Recent activity from two contributors helps, but there is no organizational backing shown.
The repository has zero stars, forks, and watchers. For a package only 167 days old this is limited supporting evidence, not proof of abandonment, and recent release and commit activity compensate.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and maintenance gap for a package handling authentication flows.
The repository has no security policy. That leaves reporting and response expectations undocumented, although recent commits and releases provide some compensating maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4.24 || ^14.1.0 | — | — |
typo3/cms-fluid Version ^13.4.24 || ^14.1.0 | — | — |
typo3/cms-backend Version ^13.4.24 || ^14.1.0 | — | — |
typo3/cms-extbase Version ^13.4.24 || ^14.1.0 | — | — |
typo3/cms-frontend Version ^13.4.24 || ^14.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.