The repository includes tests, a release note for this version, and Dependabot, but no commits in the last three months. The package's declared GPL-2.0+ license conflicts with the detected MIT license, and the linked repository does not name or mention this package.
57%
Total Score
50
81
50
The manifest declares GPL-2.0+, while the artifact license file is detected as MIT; the repository also has a license file, but the release's licensing is still inconsistent and needs clarification.
This is the only release, published over three years ago, with no releases in the last 12 months. That leaves meaningful abandonment risk despite the repository remaining available.
The repository recorded zero commits and zero active maintainers in the last three months. This is a concrete sign of limited recent maintenance for a package with only one release.
The linked repository name does not match the package name and its README does not mention the package. That raises caution that the source repository may not clearly belong to this package.
All five workflows were analyzed with no untrusted checkouts, script injection, or audit findings. However, all 17 action references are unpinned, which is a supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^10.4 || ^11.5 || ^12.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.