Clear licensing, release notes, and a focused README support adoption, with the repository tied to an organization. Pin v1.0.6 and verify compatibility with your TYPO3 target.
65%
Total Score
75
93
50
The package has seven releases over about two years, but only one release in the last 12 months, indicating a slower maintenance pace.
There were no commits or active maintainers in the last three months, which weakens evidence of current maintenance despite the recent repository push.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The single workflow was fully analyzed with no untrusted checkout or script-injection trigger, but both action references are unpinned and high-confidence template-injection findings remain hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 | — | — |
typo3/cms-backend Version ^12.4 | — | — |
typo3/cms-extbase Version ^12.4 | — | — |
typo3/cms-frontend Version ^12.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.