The package includes clear installation guidance, repository tests, and release notes covering this version. Fix the workflow templating and pin its six actions before relying on automated publishing.
70%
Total Score
75
100
92
67
The package is brand new, with two releases published within the same day and no established release track record. This limits evidence of long-term maintenance and compatibility.
All eight recent commits came from one contributor, so maintenance depends entirely on a single person and has limited handoff resilience.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is not evidence of a vulnerability by itself.
Both workflows were analyzed completely and use no untrusted checkout or script-injection trigger, but all six action references are unpinned and the publishing workflow has two high-confidence template-injection findings. These are workflow hygiene and release-integrity concerns even without a dangerous trigger.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^10.4 || ^12.4 || ^13.4 || ^14.3 | — | — |
typo3/cms-fluid Version ^10.4 || ^12.4 || ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.