Adds phone number functionality to TYPO3 based on Google's libphonenumber API.
67%
Total Score
caution
Usable with caveats: active maintenance is offset by a single contributor and weak workflow safeguards.
The repository is owned by an individual user rather than an organization, so the single-contributor concentration has no observed organizational handoff shown by this signal.
All 8 commits in the last 3 months came from one contributor, giving the project a single-person bus factor. That concentration increases abandonment and handover risk despite recent activity.
The repository has no SECURITY.md or other declared security policy. For a package that processes phone-number data, this is a real transparency and response-process gap.
Both workflows were analyzed, but all 12 action references are unpinned; one workflow has top-level write permissions and a high-confidence bot-conditions finding. The pull_request_target workflow has no untrusted checkout or script-injection sink, so this is a workflow-hygiene caution rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.3.4 | — | — |
simonschaufi/typo3-support Version ^3.1.2 | — | — |
giggsey/libphonenumber-for-php Version ^8.13.55 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.