README, tests, release notes, licensing, and a matching repository make the project transparent. CI has six unpinned actions and no security policy or scanning, leaving maintenance and build hygiene weaker than its documentation.
62%
Total Score
75
100
88
75
This is a young package with one release, published 104 days ago, so there is little release history to demonstrate sustained maintenance.
There were zero commits and zero active maintainers in the past three months, despite the repository being only 104 days old. This provides no evidence of ongoing maintenance after the initial release.
Composer build tooling is present, but no security scanning tools were detected, leaving an avoidable visibility gap for dependency and repository security issues.
The repository has no security policy, so users have no documented security-reporting path or disclosure expectations.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all six action references are unpinned, weakening build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4.24 || ^14.3.0 | — | — |
typo3/cms-fluid Version ^13.4.24 || ^14.3.0 | — | — |
typo3/cms-backend Version ^13.4.24 || ^14.3.0 | — | — |
typo3/cms-extbase Version ^13.4.24 || ^14.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.