The project has recent releases, tests, release notes, and a matching organization-backed repository. Workflows use six unpinned actions, and there has been no commit activity in the past three months, which weakens maintenance and build transparency.
78%
Total Score
88
100
89
50
The repository recorded zero commits and zero active maintainers in the past three months, despite the latest release being about three months old; this is a maintenance warning, though the recent release history partly offsets it.
The repository has zero stars, forks, and watchers, indicating limited external adoption. Popularity is supporting evidence rather than a decisive health measure, and the release and repository activity provide stronger context.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all six action references are unpinned, which weakens build reproducibility and supply-chain transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sabre/vobject Version ^4.5 | — | — |
typo3/cms-seo Version ^13.4 | — | — |
remind/extbase Version ^3.0.0 | dev-develop | — | — |
typo3/cms-core Version ^13.4 | — | — |
typo3/cms-form Version ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.