A clear README, release notes for this version, and organization-backed repository improve transparency. The modest dependency set and matching source repository are reassuring, but the small community leaves less outside review.
64%
Total Score
75
100
89
50
The repository recorded zero commits and zero active maintainers in the last three months, weakening evidence of ongoing maintenance despite a recent push and release history.
Six stars and three forks indicate a small user and contributor community, so there is limited outside review and resilience if the primary maintainer stops contributing. This is a caution for confidence, not evidence that a small package is unhealthy by itself.
Composer build tooling is present, but no security-scanning tooling was detected. The missing scanner is a maintenance and assurance gap rather than a severe risk on its own.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
The only workflow was fully analyzed without dangerous triggers, untrusted checkouts, or audit findings. However, both action references are unpinned, so their contents can change without a repository change.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.0 | — | — |
typo3/cms-backend Version * | — | — |
typo3/cms-extbase Version * | — | — |
symfony/rate-limiter Version ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.