The package is licensed, documented, actively released, and backed by an organization with security tooling and a policy. Its only notable concern is concentrated recent commit activity, so continuity depends heavily on one contributor.
82%
Total Score
88
100
83
Only one contributor made all 392 commits in the last 3 months, creating a meaningful continuity risk. Organization backing provides some handoff capacity, but no second active contributor is shown.
All 13 workflows were analyzed, all have read-only permissions, and no audit findings or untrusted checkouts were detected. Twenty-one of 66 action references are unpinned, a moderate reproducibility weakness, but not severe enough to outweigh the clean audit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^7.10 || ^8.0 | — | — |
typo3/cms-backend Version ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.