Its clear README, matching repository, release notes, and explicit GPL-3.0 license make the package easy to understand. No release or repository activity has appeared since July 2023, and workflow hygiene adds avoidable supply-chain exposure.
44%
Total Score
0
80
50
The latest release was published in July 2023, and there were no releases in the following 12 months of the observed history. This long release gap materially raises abandonment risk despite an earlier cadence of eight releases.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the release gap. The repository is not archived, but there is no recent activity showing ongoing maintenance.
The repository has no security policy, leaving maintainers' vulnerability-reporting process unclear. This is a transparency gap, though the package's README and identifiable source repository provide some compensating context.
The sole workflow has a high-confidence template-injection finding and both action references are unpinned. No untrusted checkout or script-injection path was detected, so this is workflow hygiene and supply-chain exposure rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 | — | — |
typo3/cms-dashboard Version ^12.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.