Usable with caveats: it has a recent stable release, clear licensing, a matching repository, and documented release notes. However, the repository shows no commits or active maintainers in the last three months, and its security-policy and workflow permission hygiene are limited.
72%
Total Score
50
100
89
75
The repository is owned by nitsan-technologies, but the owner is classified as a user rather than an organization. This offers limited evidence of organizational backing and does not compensate for the thin recent activity.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, even though the assessed release is recent. This weakens evidence of ongoing maintenance and creates some abandonment risk.
The repository has 0 stars, 0 forks, and 1 watcher. This provides little evidence of broad community review or adoption, although popularity is supporting evidence rather than a verdict.
Composer is used as a build tool, but no security-scanning tools were detected. The missing scanner is a transparency gap, though it is not by itself evidence that the package is unsafe.
No repository security policy was found. This leaves vulnerability-reporting and response expectations unclear, which is a maintenance and transparency gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12 || ^13 || ^14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.