It has a clear license, a small dependency surface, and recent work from two contributors. The workflow leaves one action unpinned and the repository has no security policy, so release hygiene is not perfect.
86%
Total Score
88
100
94
50
The repository has two new issues and one new pull request in the last month, but no issues or pull requests were closed or merged in that period. The open backlog is a modest maintenance caution.
Composer is used as a build tool, providing basic build structure. No security scanning tool was detected, which leaves a modest transparency gap.
The repository has no security policy. This does not show unsafe behavior, but it gives users no documented process for reporting vulnerabilities.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings. However, its one action use is unpinned, so workflow supply-chain hygiene is weaker than ideal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-form Version ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.