The release includes a documented security fix, release notes, repository tests, and a valid license. Its workflow references are unpinned, and no repository security policy or scanning is reported.
10%
Total Score
0
40
50
Packagist marks the entire package as abandoned, with no replacement package supplied. This is a direct warning that future maintenance and support should not be expected.
Only four releases were published, and none appeared in the last 12 months; the latest release was published about 6 years ago. This strongly indicates the package is no longer maintained.
The repository had no commits and no active maintainers in the last 3 months. Together with the archived state, this confirms the lack of current development activity.
The linked repository is archived and was last pushed about 5 years ago. Archiving makes ongoing fixes and compatibility work unlikely.
No repository security policy is reported. For a package whose latest release advertises a security fix, the absence of a published reporting path weakens transparency.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-11070 t3g/svg-sanitizer is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.0.3. | 0.0.0 - 1.0.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^8.7.13 || ^9.2 || ^10.1 | — | — |
typo3/cms-extbase Version ^8.7.13 || ^9.2 || ^10.1 | — | — |
typo3/cms-install Version ^8.7.13 || ^9.2 || ^10.1 | — | — |
enshrined/svg-sanitize Version ^0.13.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.