Documentation and release notes support straightforward adoption. The project has active organizational maintenance, though all three workflow actions are unpinned and no security policy is published.
88%
Total Score
100
100
94
50
The repository uses Composer build tooling but reports no security-scanning tools. That leaves a modest assurance gap, without outweighing the strong maintenance evidence.
No security policy was found in the linked repository. This is a transparency and incident-handling gap, but it is moderated by the active, organization-backed project.
Both workflows were fully analyzed with no injection, untrusted-checkout, or severity findings, and no workflow has top-level write permissions. However, all 3 of 3 action references are unpinned, creating a minor reproducibility and action-integrity hygiene concern.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-26216 typo3fluid/fluid is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.0.0 - 2.0.8, 2.1.0 - 2.1.7, 2.2.0 - 2.2.4, 2.3.0 - 2.3.7, 2.4.0 - 2.4.4, 2.5.0 - 2.5.11 and 2.6.0 - 2.6.10. | 2.0.0 - 2.0.82.1.0 - 2.1.72.2.0 - 2.2.4 +4 more | High |
CVE-2020-15241 typo3fluid/fluid is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.0.0 - 2.0.5, 2.1.0 - 2.1.4, 2.2.0 - 2.2.1, 2.3.0 - 2.3.5, 2.4.0 - 2.4.1, 2.5.0 - 2.5.5 and 2.6.0 - 2.6.1. | 2.0.0 - 2.0.52.1.0 - 2.1.42.2.0 - 2.2.1 +4 more | Medium |
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.