Repository tests and release notes provide useful coverage for consumers. Composer and Dependabot tooling are present, but the single maintainer and absent security policy leave limited resilience.
45%
Total Score
25
83
50
Only two releases were published, both on 30 May 2023, and there have been no releases in over three years. The stable version offers maturity, but the long release gap is a substantial abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing prolonged inactivity. No provided signal demonstrates current maintenance capacity.
One registry maintainer is consistent with a small, individually owned package, but it leaves little apparent publishing redundancy when combined with the absence of recent repository activity.
The repository has no security policy. This does not prove a security problem, but it reduces transparency about how dependency issues and vulnerability reports are handled.
All 17 analyzed action references are unpinned, so workflow builds can resolve changing upstream code. The audit found no untrusted checkouts, script injection, high-severity findings, or top-level write permissions, which limits the risk to workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^10.4 || ^11.5 || ^12.1 | — | — |
symfony/rate-limiter Version ^5.0 || ^6.0 | — | — |
symfony/options-resolver Version ^5.4 || ^6.0 | — | — |
ssch/typo3-psr-cache-adapter Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.