The organization-backed project includes tests, release notes, and a clear package match. Workflow actions are unpinned, and there is no security policy or automated security scanning; recent work is concentrated in one contributor.
78%
Total Score
67
100
94
50
All recent activity comes from one contributor, creating a thin short-term maintenance base; organization ownership provides some capacity for handoff.
There was one commit in the last 3 months, so recent implementation activity is limited, but the current release and broader release history provide compensating evidence.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and monitoring gap rather than evidence of unsafe code.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Both workflows were analyzed successfully with no high-confidence audit findings or dangerous trigger sinks. However, all 6 action references are unpinned, which weakens build reproducibility, and neither workflow has a top-level permissions block.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
remind/headless Version ^5.0 | dev-develop | — | — |
georgringer/news Version ^12.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.