The project has only two releases in the last year and three open issues, with no recent issue or pull-request movement. Stable versioning, a clear README, and a small runtime dependency set support adoption, but pin this version and monitor maintenance.
67%
Total Score
67
100
94
50
There were zero commits and zero active maintainers in the last three months. Recent publishing and a repository push provide some context, but this still indicates a meaningful maintenance slowdown.
The repository has three open issues and no issues or pull requests were created, closed, or merged in the last month. This is a modest sign of limited visible maintenance activity.
Composer is used for the build, but no security scanning tools were detected. The missing scanning is a hygiene weakness rather than evidence that the package is unsafe.
The repository has no security policy. That reduces transparency around vulnerability reporting and response expectations.
The only workflow was fully analyzed with no dangerous triggers or audit findings, but its single action reference is unpinned and the workflow lacks a top-level permissions block. These are moderate reproducibility and least-privilege gaps, not severe risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.