Package Health

typo3headless/typo3ai

The repository remains active enough to be identifiable, with organization backing, release notes, and a usable README. Workflow checks are weak, with all eight actions unpinned and high-confidence bot-condition findings; the license file is present and consistent with the declared GPL-2.0-or-later terms.

Latest v2.0.1PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Health Score Breakdown

Release historycaution

The package has had no registry release in roughly two and a half years, with zero releases in the last 12 months. This materially raises maintenance and abandonment risk, although the repository is not archived and a stable release exists.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months. The repository was pushed more recently, but the observed recent commit inactivity still weakens confidence in ongoing maintenance.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. That creates some uncertainty that the linked repository is the package's intended source, despite the repository's organization ownership and matching TYPO3 context.

Workflow auditcaution

All 8 of 8 action references are unpinned, and high-confidence bot-condition findings affect both auto-approval and auto-merge workflows. The pull_request_target trigger has no untrusted checkout or script-injection sink, so these are workflow-hygiene concerns rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Łukasz Uznański
Oskar Dydo

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^12.4
openai-php/client
Version ^0.8.1

Weekly Downloads

Info

Last Published
2 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform