Documentation, licensing, and security scanning are strong. The sole recent contributor and 26 unpinned workflow actions leave meaningful maintenance and build-integrity caveats.
78%
Total Score
83
100
83
All 118 recent commits came from one contributor, creating a real continuity risk despite the repository being owned by an organization.
All 18 workflows were analyzed, use read-only permissions, and showed no audit findings or untrusted checkout sinks. However, 26 of 35 action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 || ^14.3 | — | — |
typo3/cms-setup Version ^12.4 || ^13.4 || ^14.3 | — | — |
typo3/cms-backend Version ^12.4 || ^13.4 || ^14.3 | — | — |
web-auth/webauthn-lib Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.