Documentation, licensing, and recent work provide a solid maintenance baseline. The install-time hook and modest issue activity merit normal deployment scrutiny.
72%
Total Score
75
100
67
A post-autoload-dump install-time script runs during Composer installation, adding some execution surface. No other lifecycle scripts or adverse evidence were provided.
The package and repository are owned by the same individual account rather than an organization. That is transparent ownership, though it provides less formal handoff capacity than organizational backing.
There are 16 open issues and no issue or pull-request activity in the last month. This is a mild transparency concern, but recent commits and releases provide compensating maintenance evidence.
All 53 analyzed action references are unpinned, and the audit found a high-confidence template-injection issue; a low-confidence cache-poisoning finding is additional hygiene debt. No pull_request_target or workflow_run triggers, untrusted checkouts, or script injections were found, which limits the practical severity.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-8727 tomasnorre/crawler is vulnerable to Deserialization of Untrusted Data in versions 12.0.0 - 12.0.11 and 0.0.0 - 11.0.13. | 0.0.0 - 11.0.1312.0.0 - 12.0.11 | High |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
doctrine/dbal Version ^3.10 || ^4.3 | — | — |
typo3/cms-seo Version ^12.4 || ^13.4 | — | — |
typo3/cms-core Version ^12.4 || ^13.4 | — | — |
typo3/cms-info Version ^12.4 || ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.