The project has recent releases, a clear license, documentation, and ongoing commits. Maintenance depends on one contributor, while workflow references are unpinned and a high-confidence template-injection warning needs attention.
68%
Total Score
75
100
89
67
All three recent commits came from one contributor, so maintenance is concentrated and continuity depends on a single person.
The repository has only 2 stars and no forks or watchers, indicating limited external adoption; this is supporting evidence rather than a decisive health problem.
Composer build tooling is present, but no security-scanning tool was detected; this is a modest transparency and assurance gap for a package with active workflows.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
Both workflows scope permissions at job level, but all 9 action references are unpinned. A high-confidence template-injection finding appears in deploy.yml; the low-confidence cache findings are hygiene concerns only.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.3 | — | — |
typo3/cms-backend Version ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.