The repository is active and the release includes tests and notes, but recent commit activity is absent and all six workflow actions are unpinned. Use remind/headless instead.
42%
Total Score
75
81
75
Packagist marks the entire package abandoned and names remind/headless as its replacement. This is a major adoption concern even though the repository and release history show recent activity.
The repository recorded zero commits and zero active maintainers in the last 3 months. This is a meaningful maintenance warning, although the recent push and release history provide some counterevidence.
Composer is used for the build, but no security scanning tool was detected. That is a transparency and hygiene gap for a dependency project.
The repository has no security policy. This weakens disclosure transparency, though it is less serious than abandonment because the project has organizational backing and recent releases.
Both workflows were analyzed completely and have no dangerous triggers, untrusted checkouts, or audit findings. However, all 6 of 6 action references are unpinned, leaving workflow dependencies exposed to moving versions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
friendsoftypo3/headless Version ^4.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.