Recent release activity, tests, and release notes support ongoing maintenance. All 17 workflow actions are unpinned, and one contributor made every recent commit; clarify the license before adopting.
68%
Total Score
75
100
94
75
The manifest declares MIT, but the artifact license file is detected as GPL-2.0; although a license file exists, the mismatch creates a material licensing ambiguity.
One contributor made all three commits in the last three months, leaving maintenance dependent on a single active person and increasing continuity risk.
No repository security policy was found. This is a transparency gap, though the package's dependency-update tooling provides some compensating maintenance evidence.
All five workflows were analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all 17 action references are unpinned, weakening build reproducibility and update integrity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.3 | — | — |
pagerfanta/core Version ^4.7 | — | — |
typo3/cms-fluid Version ^14.3 | — | — |
webmozart/assert Version ^2.1 | — | — |
typo3/cms-extbase Version ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.