The repository has a clear README, release notes, tests, changelog, license, and security policy. Workflow references are all unpinned, and no repository security-scanning tool is reported, leaving build reproducibility and monitoring weaker than the otherwise solid project structure.
66%
Total Score
50
100
81
100
This is the package's first release, published today, so there is no demonstrated release track record yet; the initial release notes provide some transparency but cannot show sustained maintenance.
No commits or active maintainers were observed in the last three months, but the repository and release are only one day old, so this is an immature history rather than evidence of a long-term collapse.
Composer build tooling is present, but no security-scanning tool is reported, leaving a modest gap in repository hygiene.
Version 0.1.0 is not a stable major release, which signals an early-stage API and limited maturity; it is not marked as a prerelease, which partly offsets that concern.
The single workflow was fully analyzed, uses read-only permissions, and has no reported dangerous triggers or audit findings. However, all seven action references are unpinned, weakening reproducibility and exposing the workflow to reference changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/mime Version ^7.2 | — | — |
doctrine/dbal Version ^4.2 | — | — |
symfony/mailer Version ^7.2 | — | — |
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.