The repository has recent release activity and clear packaging, tests, and licensing. Maintenance remains concentrated in one contributor, while all six workflow actions are unpinned.
72%
Total Score
67
94
75
One contributor made all two commits in the last three months, leaving maintenance highly concentrated. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository recorded two commits in the last three months, showing recent activity but at a low level for an actively evolving integration.
Composer build tooling is present, but no security-scanning tool was detected. That is a maintenance and assurance gap, not evidence that the package is unsafe.
The repository has no security policy, reducing transparency about how users should report vulnerabilities and receive fixes.
Both workflows were analyzed successfully with no detected injection or credential findings, but all six action references are unpinned. This creates avoidable workflow supply-chain drift.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 | ^13.4 | — | — |
typo3/cms-form Version ^12.4 | ^13.4 | — | — |
getbrevo/brevo-php Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.