The package includes tests, release notes, a license, and clear documentation. Organization backing and read-only workflow permissions add useful safeguards, but the small public contributor base and unpinned actions limit resilience.
72%
Total Score
88
100
89
100
One contributor made 100% of the 127 recent commits, creating a real continuity risk; organization ownership provides some capacity to hand off maintenance but does not demonstrate a second active contributor.
The repository has one star and no forks, offering little community validation; this is supporting evidence only and is outweighed by its strong recent activity and organization backing.
Version 0.7.1 is not a stable major release, so compatibility may still change despite the absence of prerelease labeling.
All 10 workflows have read-only permissions and no audited high-risk findings or untrusted checkouts. However, 20 of 33 action references are unpinned, leaving avoidable build-reproducibility and action-update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 || ^14.3 | — | — |
typo3/cms-form Version ^12.4 || ^13.4 || ^14.3 | — | — |
typo3/cms-fluid Version ^12.4 || ^13.4 || ^14.3 | — | — |
typo3/cms-extbase Version ^12.4 || ^13.4 || ^14.3 | — | — |
typo3/cms-frontend Version ^12.4 || ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.