Its README clearly warns that migrations are incomplete and irreversible, while the workflow uses an unpinned action. The repository is not archived and the package has a declared license, but those positives do not offset about five years without releases or commits.
48%
Total Score
25
75
50
The package has only three releases, all around its first release in May 2021, and none in the last 12 months. About five years without a release is a substantial abandonment concern for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing prolonged inactivity. The repository is still present, but there is no recent maintenance evidence.
Only one registry account has publishing access. For a user-owned project this leaves little visible publishing redundancy, and the lack of recent releases provides no compensating activity.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but its one action reference is unpinned. That is a limited reproducibility and supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^9.5.0 || ^10.4.0 | — | — |
typo3/cms-extbase Version ^9.5.0 || ^10.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.