The package includes a clear README, license, repository, and release notes. Its small dependency set and lack of install scripts reduce operational risk, but maintenance history is too short to establish long-term reliability.
66%
Total Score
100
79
67
This is the first registry release, published today, so there is no release history or cadence to demonstrate sustained maintenance. That is an evidence gap rather than proof of abandonment.
Composer is used for builds, but no security scanning tooling was detected. For a package that reports security-related installation data, this is a modest transparency and maintenance gap.
The linked repository has no security policy. That makes vulnerability reporting and disclosure expectations less clear for a package used in TYPO3 installations.
Version 0.3.2 is not a stable major release, although it is not marked as a prerelease and recent releases show no prerelease activity. This modestly limits maturity evidence.
Both workflows were analyzed without dangerous triggers or audit findings, and one scopes permissions at job level. However, all five action references are unpinned, leaving the build dependent on moving external action code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 || ^14.3 | — | — |
typo3/cms-backend Version ^12.4 || ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.