It includes a clear license, tests, extensive documentation, and a matching organization-owned repository. The build uses security scanning, but its two workflow actions are unpinned.
44%
Total Score
0
70
50
The package has only one release, published about 3 years and 8 months ago, with no releases in the last 12 months. That is strong evidence of limited ongoing maintenance for a library dependency.
The repository recorded 0 commits and 0 active maintainers over the last 3 months, consistent with the package's long release gap. This materially raises abandonment risk.
The repository has 0 stars, 0 forks, and 0 watchers. Popularity is only supporting evidence, but these counters provide no indication of an active user or contributor community.
The repository has no security policy. For an extension that exposes routing and authentication-related middleware, this is a meaningful transparency and vulnerability-reporting gap.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its two action references are unpinned. That leaves routine build execution exposed to unreviewed action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^11.5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.