Strong organization backing, a clear README, tests in the repository, and a security policy support adoption. Maintenance has gone quiet since this release, and all four workflow actions are unpinned, so future updates deserve extra scrutiny.
62%
Total Score
75
83
75
The package has 27 releases since August 2018, but none in the last 12 months and its latest registry release was in December 2024, indicating a meaningful maintenance gap.
The repository recorded no commits and no active maintainers in the last 3 months. This is a concern for ongoing maintenance, although the project is not archived and has organizational backing.
Both workflows were analyzed successfully with no dangerous audit findings, but all 4 action references are unpinned, leaving routine build dependencies less reproducible.
| Title | Versions | Severity |
|---|---|---|
CVE-2019-11830 typo3/phar-stream-wrapper is vulnerable to Deserialization of Untrusted Data in versions 2.0.0 - 2.1.1 and 3.0.0 - 3.1.1. | 2.0.0 - 2.1.13.0.0 - 3.1.1 | Critical |
CVE-2019-11831 typo3/phar-stream-wrapper is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 2.0.0 - 2.1.1 and 3.0.0 - 3.1.1. | 2.0.0 - 2.1.13.0.0 - 3.1.1 | Critical |
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.