Package Health

straschek-io/typo3-tor-blocker

The package includes clear installation guidance, repository tests, and release notes covering this version. Fix the workflow templating and pin its six actions before relying on automated publishing.

Latest v1.1.0PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package is brand new, with two releases published within the same day and no established release track record. This limits evidence of long-term maintenance and compatibility.

Repo bus factorcaution

All eight recent commits came from one contributor, so maintenance depends entirely on a single person and has limited handoff resilience.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is not evidence of a vulnerability by itself.

Workflow auditcaution

Both workflows were analyzed completely and use no untrusted checkout or script-injection trigger, but all six action references are unpinned and the publishing workflow has two high-confidence template-injection findings. These are workflow hygiene and release-integrity concerns even without a dangerous trigger.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Michael Straschek

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^10.4 || ^12.4 || ^13.4 || ^14.3
—
—
typo3/cms-fluid
Version ^10.4 || ^12.4 || ^13.4 || ^14.3
—
—

Weekly Downloads

Info

Last Published
14 days ago
Created
14 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform