The package has clear documentation, repository tests, a changelog, and read-only workflow permissions. Security scanning and a security policy are absent, while the four referenced actions are not pinned.
62%
Total Score
50
100
88
67
This is the first release, published 0 days ago, so there is no release track record yet. That is expected for a new package but leaves maintenance maturity unproven.
The repository recorded 0 commits and 0 active maintainers in the past three months. Because the package was released today, this is mainly an unproven maintenance signal rather than evidence of abandonment.
Composer build tooling is present, but no security scanning tools were detected. That weakens automated supply-chain hygiene for a package intended for production TYPO3 projects.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented.
Both workflows use read-only permissions and the audit found no high-confidence workflow findings or untrusted-code sinks. However, all 4 referenced actions are unpinned, which creates avoidable reproducibility and action-substitution risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 || ^14.3 | — | — |
typo3/cms-fluid Version ^12.4 || ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.