The repository lacks a security policy, and its single workflow uses an unpinned action. Documentation is present, the release includes notes, and recent commits show ongoing work with two contributors.
79%
Total Score
100
100
88
75
The artifact includes a license file and the repository also has one, but the declared MIT license conflicts with the detected GPL-3.0 text. That mismatch creates a real licensing concern.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and hygiene gap, not evidence of unsafe code by itself.
No repository security policy was found, leaving vulnerability-reporting expectations unclear. This lowers transparency but does not independently make the release unfit.
The one workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Its only action use is unpinned, which is a mild reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.