The project is actively maintained, with frequent releases and two evenly active contributors. It has a clear license and README, but its workflow hygiene needs attention.
66%
Total Score
100
100
86
67
Composer is used for builds, but no security scanning tools are reported. The missing scanning is a modest transparency and hygiene gap, not evidence of unsafe code by itself.
The repository has no security policy. For a maintained web extension this leaves vulnerability reporting and response expectations less clear, lowering transparency.
The assessed version is 14.6.6, but the indicator reports 13.6.4 as the latest version, creating an unresolved metadata inconsistency. The release is nevertheless marked stable and not prerelease, so this is a caution rather than a severe release risk.
All 10 analyzed action references are unpinned, and one workflow grants top-level write access, creating reproducibility and permission-hygiene concerns. The auditor also found high-confidence template-injection patterns, but no untrusted checkout or dangerous trigger was reported to corroborate them as a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.