The project is only 45 days old with two releases, so long-term stability is not yet demonstrated. Two active contributors, repository tests, a clear license, and read-only workflow permissions provide useful support; the missing security policy and unpinned actions remain weaknesses.
72%
Total Score
100
100
83
75
The package is 45 days old and has only two releases, both published on the same day; this is too little history to establish durable maintenance, though it is not evidence of abandonment.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this modestly limits external validation but does not establish a maintenance problem.
Composer is used for the build, but no security-scanning tool was detected. The build setup is appropriate, while the missing scanning capability is a hygiene weakness.
The linked repository has no security policy. That reduces transparency about vulnerability reporting and response expectations, particularly for an extension that performs security-related checks.
Both workflows use read-only permissions, but all five analyzed action references are unpinned. The publish workflow also has two high-confidence template-injection findings; template injection is a workflow hygiene concern here, while the unpinned references make builds less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.0 | — | — |
typo3/cms-backend Version ^13.4 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.