The package includes a clear README, tests, release notes, and a repository that matches its package name. Its license and organization backing provide useful continuity.
72%
Total Score
67
100
94
75
All three-month commit activity is concentrated in one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only one commit from one active maintainer was recorded in the last three months, which indicates limited recent development activity despite the broader release history.
Composer is used for builds, but no repository security scanning tools were detected, leaving a modest security-process gap.
The repository has no documented security policy, reducing transparency about vulnerability reporting and response.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 6 action references are unpinned, so workflow dependencies are less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
friendsoftypo3/headless Version ^4.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.