Its focused dependency set and clear README keep adoption straightforward. Organization ownership and recent publishing offer continuity, but limited independent activity leaves maintenance capacity thin.
68%
Total Score
67
100
100
50
One contributor made 100% of the recent commits. Organization ownership provides some handoff capacity, but no second active contributor is visible in this period.
The repository had only 1 commit in the last 3 months from 1 active maintainer. Recent registry releases compensate partly, but the source activity itself is thin.
The repository has no security policy. For an extension handling backend authentication tokens and cross-domain cookies, this reduces transparency around vulnerability reporting.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings. Its one action reference is unpinned, which is a modest reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.3.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.