The project has a small footprint and no recorded commits in the last three months. Its release notes and matching repository help, but workflow injection risk, unpinned actions, and missing security policy reduce confidence.
58%
Total Score
50
67
50
The package has only four releases since December 2020, with no releases in the last 12 months and a median interval of about 20 months. This indicates a slow maintenance cadence, though the latest release is established rather than experimental.
The repository recorded zero commits and zero active maintainers in the last three months. That weakens evidence of ongoing maintenance, even though the repository is not archived and was pushed previously.
The repository has only 2 stars and 2 forks, showing a small community footprint. This is supporting evidence of limited adoption rather than a standalone health verdict.
The linked repository has no security policy. For a small extension this is a hygiene gap, but it leaves vulnerability-reporting expectations and response procedures unclear.
The publishing workflow contains one high-confidence template-injection finding, and both of its action references are unpinned. No untrusted checkout or script-injection path was reported, so this is a workflow-hygiene concern rather than a severe dependency verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^10.4 || ^11.5 | — | — |
in2code/powermail Version ^7.5 || ^8.5 || ^9.0 || ^10.9 | — | — |
sjbr/static-info-tables Version ^6.9 || ^11.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.