公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-27 21:03 UTC

hauptsacheNet / typo3-mcp-server

One MCP endpoint connects your TYPO3 site to Claude, Cursor, n8n, and any AI tool — safely through workspaces.

PHPGPL-2.0★ 91 星标⑂ 21 复刻始于 2025年4月在 GitHub 上查看 ↗

hauptsacheNet/typo3-mcp-server 的健康指数为 100 分中的 64 分,处于「中等」区间。 其得分最高的类别是Vitality(84/100),最低的是Security(46/100)。 最近一次更新在今天。 近期的大部分工作由 1 位贡献者完成。

64
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

64
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

2 关注者53 个公开仓库始于 2013年8月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Packagisthn/typo3-mcp-serverv0.4.47,0251635 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

84良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 0 天前
17.3/36提交节奏 — 52 周中有 25 周有提交
17.2/18提交量 — 最近一年 81 次提交
10/10OpenSSF Scorecard:Maintained — 24 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year81
human_commit_share1
days_since_last_push0
active_weeks_last_year25

发布纪律

90优秀
评分方式
27/27有发布版本 — 已发布 15 个发布版本
36/36发布时效 — 最近一次发布版本于 35 天前
27/27发布节奏 — 约每 12.3 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — Project has not signed or included provenance with any releases.
所用输入
releases_count15
latest_release_tagv0.4.4
releases_from_tags
days_since_latest_release35
mean_days_between_releases12.3

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

50中等 · 占总体的 18%

流行度与采用

48存在风险
评分方式
31.7/60星标 — 91 个星标
10.8/25复刻 — 21 个复刻
5.8/15关注者 — 12 位关注者
所用输入
forks21
stars91
watchers12
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

50中等
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(GPL-2.0)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
51.3/80月度下载量 — packagist 合计每月 7,025 次下载
2/20注册表被依赖数 — 1 个软件包依赖它
所用输入
packageshn/typo3-mcp-server
dependents1
ecosystemspackagist
total_downloads29,978
monthly_downloads7,025

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

60中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
2.7/22.5提交分布 — 头号贡献者编写了 88% 的提交
10.8/13.5贡献者广度 — 8 位贡献者
10/10OpenSSF Scorecard:Contributors — project has 3 contributing companies or organizations -- score normalized to 10
所用输入
bus_factor1
contributors_sampled8
top_contributor_share0.879
评分方式
29.2/46.8议题解决 — 62% 的议题已关闭
32.2/38.3PR 接受 — 已裁定的 PR 中 59/70 已合并
3/15OpenSSF Scorecard:Code-Review — Found 8/30 approved changesets -- score normalized to 2
所用输入
merged_prs59
open_issues9
closed_issues15
issue_closed_ratio0.625
closed_unmerged_prs11
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
3.4/25所有者影响力 — hauptsacheNet 有 2 位关注者
24.6/25既往记录 — 53 个公开仓库,账户约 12 年
所用输入
followers2
owner_typeOrganization
is_verified
owner_loginhauptsacheNet
public_repos53
account_age_days4,724
评分方式
25/25已发布且可解析 — packagist 上有 1 个软件包
35/35发布时效 — 最近一次发布于 35 天前
20/20版本历史 — 16 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packageshn/typo3-mcp-server
ecosystemspackagist
any_deprecated
min_days_since_publish35

工程质量

基础的工程与文档实践是否到位?

73良好 · 占总体的 20%

工程实践

62中等
评分方式
24/24CI 工作流 — 3 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
14/20OpenSSF Scorecard:CI-Tests — 23 out of 30 merged PRs checked by a CI test -- score normalized to 7
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

90优秀
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://hauptsachenet.github.io/typo3-mcp-server/
10/10仓库描述
10/10主题标签 — 4 个主题标签
0/10Wiki
所用输入
topicsmcp, mcp-server, typo3, typo3-extension
has_wiki
homepagehttps://hauptsachenet.github.io/typo3-mcp-server/
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

46存在风险 · 占总体的 16%

安全态势

46存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
1.8/2.5CI-Tests — 23 out of 30 merged PRs checked by a CI test -- score normalized to 7
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
1.5/7.5Code-Review — Found 8/30 approved changesets -- score normalized to 2
2.5/2.5Contributors — project has 3 contributing companies or organizations -- score normalized to 10
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 24 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — 无数据
5/5Pinned-Dependencies — all dependencies are pinned
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4.6
已排除计分(无数据或不适用):packaging。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

74良好 · 占总体的 0%
评分方式
45/45代理指令 — CLAUDE.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 86 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.86
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes1,890
评分方式
0/18一条命令的引导启动
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — Build/tsconfig.json
10/10可复现环境 — lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 39 次由代理编写或署名代理
0/8自动化维护 — 未观察到自动依赖更新
10/10OpenSSF Scorecard:Pinned-Dependencies — all dependencies are pinned
所用输入
has_nix
has_tests
lockfilespackage-lock.json
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configsBuild/tsconfig.json
agent_commit_share0.39
toolchain_manifests
dependency_bot_commit_share0
评分方式
27/45可类型检查的代码 — PHP,已配置类型检查(Build/tsconfig.json)
54.3/55可控的文件大小 — 采样的 155 个源文件中有 2 个超过 60KB
所用输入
primary_languagePHP
largest_source_bytes96,854
source_files_sampled155
oversized_source_files2

关键数据

91GitHub 星标
8贡献者
81最近 12 个月提交数
0距最近推送天数
15发布版本数
1巴士系数(bus factor)
9开放议题
npm, Packagist软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

更多细节

Star 与 Fork 历史 0 ★ / 21 ⇿
0Star
21Fork
14发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

048121620242122025-112026-032026-07
主版本 0次版本 3修订 11
OpenSSF Scorecard 4.6 / 10
4.6综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-27 21:02 UTC

10Binary-Artifactsno binaries found in the repo
1Branch-Protectionbranch protection is not maximal on development and all release branches
7CI-Tests23 out of 30 merged PRs checked by a CI test -- score normalized to 7
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
2Code-ReviewFound 8/30 approved changesets -- score normalized to 2
10Contributorsproject has 3 contributing companies or organizations -- score normalized to 10
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained24 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10
不适用Packagingpackaging workflow not detected
10Pinned-Dependenciesall dependencies are pinned
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
9Vulnerabilities1 existing vulnerabilities detected
直接依赖 4
注册表软件包版本约束清单文件
Packagistlogiscape/mcp-sdk-php^1.2composer.json
Packagisttypo3/cms-backend^13.4 || ^14.3composer.json
Packagisttypo3/cms-core^13.4 || ^14.3composer.json
Packagisttypo3/cms-workspaces^13.4 || ^14.3composer.json
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "mcp",
        "mcp-server",
        "typo3",
        "typo3-extension"
      ],
      "is_fork": false,
      "size_kb": 1964,
      "has_wiki": false,
      "homepage": "https://hauptsachenet.github.io/typo3-mcp-server/",
      "languages": {
        "CSS": 1433,
        "PHP": 1643545,
        "HTML": 31227,
        "Shell": 20911,
        "JavaScript": 31202,
        "TypeScript": 7183
      },
      "pushed_at": "2026-07-27T20:53:59Z",
      "created_at": "2025-04-30T08:41:37Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-22T20:41:08Z",
      "description": "One MCP endpoint connects your TYPO3 site to Claude, Cursor, n8n, and any AI tool — safely through workspaces.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "GPL-2.0",
      "default_branch": "main",
      "license_spdx_raw": "GPL-2.0",
      "primary_language": "PHP",
      "significant_languages": [
        "PHP"
      ]
    },
    "owner": {
      "blog": "www.hauptsache.net",
      "name": "hauptsache.net GmbH",
      "type": "Organization",
      "login": "hauptsacheNet",
      "company": null,
      "location": "Hamburg",
      "followers": 2,
      "avatar_url": "https://avatars.githubusercontent.com/u/5269071?v=4",
      "created_at": "2013-08-20T10:48:50Z",
      "is_verified": null,
      "public_repos": 53,
      "account_age_days": 4724
    },
    "license": {
      "state": "standard",
      "spdx_id": "GPL-2.0",
      "raw_spdx": "GPL-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.4.4",
          "kind": "patch",
          "published_at": "2026-06-22T09:28:09Z"
        },
        {
          "tag": "v0.4.3",
          "kind": "patch",
          "published_at": "2026-06-16T11:01:57Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-05-12T08:27:58Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-05-11T09:06:18Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-05-05T07:44:40Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-04-29T15:11:54Z"
        },
        {
          "tag": "v0.2.3",
          "kind": "patch",
          "published_at": "2026-04-17T13:44:03Z"
        },
        {
          "tag": "v0.2.2",
          "kind": "patch",
          "published_at": "2026-04-07T12:02:14Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-03-19T09:21:19Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-03-03T12:41:22Z"
        },
        {
          "tag": "v0.1.5",
          "kind": "patch",
          "published_at": "2026-02-16T16:02:43Z"
        },
        {
          "tag": "v0.1.4",
          "kind": "patch",
          "published_at": "2026-01-23T16:12:36Z"
        },
        {
          "tag": "v0.1.3",
          "kind": "patch",
          "published_at": "2026-01-11T16:47:52Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2025-11-25T09:23:55Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2025-07-28T09:09:12Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "2cdc3f3cf8f7a256acd040f1abfe7e41fe49ee47",
          "body": "* fix: support subdirectory installations in HTTP/OAuth routing\n\nThe MCP middleware matched request paths against root-relative literals\n(/mcp, /mcp_oauth/*, /.well-known/*) and the endpoints built absolute URLs\nfrom scheme+host only. On installations served from a subdirectory\n(e.g. https://example\n[…]\nthe site path before matching;\nendpoints and redirects include it. Root installations are unaffected\n(site path resolves to an empty string).\n\nCovered by Tests/Functional/Http/SubdirectoryRoutingTest.",
          "is_bot": false,
          "headline": "fix: support subdirectory installations in HTTP/OAuth routing (#100)",
          "author_name": "Konrad Michalik",
          "author_login": "konradmichalik",
          "committed_at": "2026-07-07T11:27:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ba4b5c8ba815058fb62dc5d566da0fc5d488ef9e",
          "body": "…s without OAuth discovery) (#101)\n\nMints a long-lived access token for a backend user without the interactive\nOAuth flow, for MCP clients that authenticate with a static Authorization\nheader instead of OAuth discovery (e.g. subdirectory installs where RFC 8414\nauthorization-server metadata discovery cannot work).\n\nUsage: vendor/bin/typo3 mcp:oauth create <username> [--ttl-days=N]\nPrints the plaintext token once (the DB stores only a hash).",
          "is_bot": false,
          "headline": "feat: add 'mcp:oauth create' to mint static access tokens (for client…",
          "author_name": "Konrad Michalik",
          "author_login": "konradmichalik",
          "committed_at": "2026-06-29T14:40:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6830569dabbf475d51b8bdd88d3f3d2cc46aadeb",
          "body": "…date (#94) (#98)\n\nPage creation failed with \"Field 'sys_language_uid' is not available for\nthis record type\" because the validation derives available fields from the\nTCA showitem, and TYPO3 never lists the language field in the `pages`\nshowitem (page translations go through the dedicated localize w\n[…]\n available during\nvalidation, mirroring how the type field is handled. The field stays out\nof the schema exposed to the client, so nothing else changes.\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(WriteTable): always allow the language control field on create/up…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-06-22T09:22:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9b8800f504c50a7f20854ddb7aad0b9708cf64e3",
          "body": "The resolver compiled a blank 'new' record and never fed the record's own\nfield values into FormDataCompiler, so any itemsProcFunc that depends on\nsibling fields saw an empty row. b13/container's tt_content.colPos\nitemsProcFunc reads tx_container_parent (and colPos) off the row to expose a\ncontainer\n[…]\nos resolves for a child, registered/unregistered colPos validate\ncorrectly, and the cache does not collide across record contexts on one pid.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix SelectItemResolver to pass record context to itemsProcFunc (#97)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-06-15T16:32:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0326a5851a5ff3011bfbca00a5d5d210006d9baf",
          "body": "Every push to main now publishes the LLM test suite's per-model\npass counts to a Google Sheet via an Apps Script web app, and the\nREADME displays live shields.io badges advertising continuous\ntesting across Anthropic, OpenAI, Mistral, and Google.\n\nThe CI side (Build/post-llm-stats.php) parses JUnit \n[…]\nns in the Apps Script header): deploy as\na web app, set INGEST_TOKEN, and add LLM_STATS_SHEET_URL +\nLLM_STATS_SHEET_TOKEN repository secrets.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add public LLM benchmark via Google Sheets + shields.io badges (#88)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-05-13T11:25:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6800308b727c440078bced24ad5b8b84c4b7523c",
          "body": "…ns (#90)\n\nTableAccessService::getAvailableFields had a two-case escape hatch that\nbypassed sub-schema filtering and returned every TCA column for:\n\n  (a) tables using foreign type notation (sys_file_reference,\n      sys_file_metadata, where ctrl.type = \"uid_local:type\"/\"file:type\")\n  (b) read-only \n[…]\nsting Office Hours element\n  on the contact page advertised colPos=1 as legitimate. Fix the\n  fixture in every LLM test that loads pages.csv.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(schema): drive read schema from showitem instead of raw TCA colum…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-05-12T08:17:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7c9924d5c5681c51f352cc80ba0c12f1ad4cfe63",
          "body": "When the backend user is inside a workspace, ReadTable's uid filter\nORed `uid IN (...)` with `t3ver_oid IN (...)` so a lookup would hit\nboth the live record and any workspace overlay pointing at it. That\nOR branch was added unconditionally, but `t3ver_oid` only exists on\ntables with versioningWS=tru\n[…]\nrated SQL — SQLite silently treats unknown\ndouble-quoted identifiers as string literals, so a behaviour-only\ntest would pass even with the broken query.\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ReadTable): skip t3ver_oid uid filter on non-workspace tables (#91)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-05-11T16:10:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "127c14e459940f172a44be363481b2af177e0326",
          "body": "…g (#89)\n\nThe LLM Tests CI job had crept from ~7 min (Apr 23) to ~16 min\n(May 8) without an obvious cause. Investigation found:\n\n1. The retry override added in PR #59 was silently no-op'd by\n   PHPUnit 13 (pulled in via testing-framework ^9.2 in PR #71).\n   PHPUnit 13 made TestCase::runTest() privat\n[…]\nmetimes gpt-5.4-mini) — a tool-description issue, not a\nCI-config issue, and now clearly visible rather than masked by\nthe majority-pass rule.\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(llm): make retries visible, fix broken retry hook, tune reasonin…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-05-09T13:43:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6e843ad188d8363d7416309a37915812c84803dc",
          "body": "Page TSconfig was previously read via BackendUtility::getPagesTSconfig(0).\nPage 0 has no rootline, so TCEFORM.tt_content.CType.removeItems and similar\nrules defined on real pages (sys_template, page records, site config) were\nsilently ignored. The LLM kept seeing removed CTypes and would happily pic\n[…]\nDataCompiler doesn't apply it (it's only read by the New Content\nElement Wizard) so a disabled CType would otherwise pass DataHandler\nwithout complaint.\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(TSconfig): resolve TCEFORM/TCEMAIN at the actual page rootline (#87)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-05-08T17:59:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d709bcf778995f85409df46093e284456efad2ef",
          "body": "Hn\\McpServer\\Service\\TableAccessService::canAccessField Checks if a field is globally disabled without taking the 'overlay' that is specified in 'types.' into account.\n\nThis causes problems for installations that disable all fields by default and enable them in user / group permissions.\n\nThe 'types.' array should be merged with the TCEFORM field config before checking the disabled status.\n\nResolves #38\n\n---------\n\nCo-authored-by: Marco Pfeiffer <marco@hauptsache.net>",
          "is_bot": false,
          "headline": "Add field visibility checks for TCEFORM configuration (#39)",
          "author_name": "Michiel Roos",
          "author_login": "Tuurlijk",
          "committed_at": "2026-05-08T16:35:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae1b45776f2c119e9e89bf37a1c6c1eaa97b96ba",
          "body": "* feat(WriteTable): support moving records via pid on update\n\nSetting `pid` on an `action=update` call (either at the top level or\ninside `data`) now moves the record to that page via DataHandler's\n`move` cmdmap, instead of being rejected as \"field cannot be set during\nrecord creation\" or as an unkn\n[…]\n *not* a top-level property.\n- `testUpdateWithTopLevelPidStillWorksAsCompatFallback` covers the\n  shim path explicitly.\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(WriteTable): support moving records by setting pid on update (#86)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-05-08T16:20:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6119fdb46915cdb28e8dcce0c4bc7cc8e463854f",
          "body": "DataHandler silently drops fields on update/create that do not exist in\nTCA `columns` — control-only fields like `sorting` (which lives in\nctrl.sortby) and plain typos alike. The tool previously accepted these\nand returned a success response, producing a \"lying success\" where the\ncaller believed the\n[…]\ndering anyway.\n\nCo-authored-by: Thomas Schmidt <backoffice@clicksgefuehle.at>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\nCo-authored-by: Marco Pfeiffer <marco@hauptsache.net>",
          "is_bot": false,
          "headline": "fix(WriteTable): reject fields without a TCA columns entry (#70)",
          "author_name": "Thomas Schmidt",
          "author_login": "contemas-tschmidt",
          "committed_at": "2026-05-08T14:34:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b1ff5d6f034f091e43cba6ad9b3b259003212833",
          "body": "…(#84)\n\nDynamicSelectItemsTest set $GLOBALS['TYPO3_CONF_VARS']['BE']['defaultPageTSconfig']\nto inject TCEFORM.tt_content.colPos.addItems for the FormDataCompiler-based\nSelectItemResolver. TYPO3 14 removed that global (Breaking #105377, deprecated\nin #101799), so the resolver only saw the static colP\n[…]\n 1 (works on\nboth TYPO3 13 and 14) and pass pid=1 to the resolver call that previously had\nno record context, so FormDataCompiler picks the rootline up.\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(tests): use page TSconfig instead of removed defaultPageTSconfig …",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-05-08T13:54:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "10a8ccdf0d9f2525856d466de58710eb3564895a",
          "body": "…olves #24) (#25)\n\nUse TYPO3's FormDataCompiler with TcaDatabaseRecord group to resolve\nthe full list of select field items, including static TCA items,\nforeign_table items, itemsProcFunc callbacks, and TSconfig\naddItems/removeItems/keepItems. This fixes validation rejecting\ndynamically added values like custom colPos from backend layouts.\n\nCloses #24\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Resolve dynamic select items via FormDataCompiler for validation (res…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-05-08T13:04:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "301a08a2e0a486b180e9279ca4c78c490f0ab3f9",
          "body": "parseSelectItems passed item labels through unchanged. When a TCA\nselect field uses integer labels — as a real-world `ranking` field on\nsys_file_metadata does on TYPO3 13 (items: 0..5 with label === value)\n— the int label flowed into the type-strict\nTableAccessService::translateLabel(string $label) \n[…]\noundary\nso all callers (TcaFormattingUtility, getAvailableTypes, WriteTable's\nauthMode formatter, getSelectFieldAllowedValues) become type-safe at\nonce.\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(GetTableSchema): cast TCA select item labels to string (#82)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-05-05T14:03:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "afbeb3db6b63a07c0e2e99c6aa739573af876599",
          "body": "…arch too (#83)\n\nSearchTool's per-table query and inline-parent lookup ran straight to\nexecuteQuery() without any listener hook, so SysFileMountRestrictionListener\n(and any future tenant/scope listener) only filtered ReadTableTool — search\ncould surface records ReadTableTool would have hidden. Mirror the dispatch\nsites and add a $source field on the event so listeners can branch on the\noriginating call site if they need to.\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(Search): dispatch BeforeRecordReadEvent so listeners restrict se…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-05-05T14:02:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c149352f9b317b392e7edacc15b5e2b089f0debd",
          "body": "* fix(ui): drop bootstrap fade class from backend module tabs\n\nThe .fade animation class is broken in TYPO3 14's default backend theme,\nleaving tab panels invisible. Removing the class makes panel switches\ninstant and works on both 13 and 14.\n\n* feat(ui): add custom MCP icon based on the official MC\n[…]\n nicely in the user menu).\n- Resources/Public/Icons/Extension.svg now contains the white-on-\n  #00AF9C variant used by the extension manager.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix tab panes and add custom MCP icons (#81)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-05-04T17:13:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "76fbade48d8781c91e1a5f922e02b165ba30e102",
          "body": "The MCP endpoint auth-check tooltip referenced a warning \"below\",\nbut the warnings are rendered above the main module.\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: correct tooltip text to point to warning above (#80)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-05-04T15:01:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3fdbf0deb02bb34b502451b9e36f9465809225f5",
          "body": "feat: support TYPO3 14.3 alongside 13.4 (#45)\n\nWidens runtime support from TYPO3 13.4-only to 13.4 || 14.3, with all\nversion-conditional behavior driven at runtime from a single TCA-based\ndetector (TableAccessService::hasPluginSubtypes()) — no version-string\nsniffing.\n\nBuild / CI\n- composer.json: ty\n[…]\neen localized\" on first translate\n    when a workspace placeholder is present.\n\nVerified\n- Functional suite green on both TYPO3 13.4 and 14.3 under the full\n  CI matrix.\n- E2E suite green.\n\nCloses #45",
          "is_bot": false,
          "headline": "Support TYPO3 14: adapt plugin handling and workspace APIs (#71)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-05-04T15:00:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7234bb741c1d4ee5ca7a885538c040385d532fd9",
          "body": "* Expose sys_file_metadata as a standalone editable table\n\nsys_file is read-only via additionalReadOnlyTables, but its embedded\nmetadata (sys_file_metadata) was silently writable through a side door:\nTableAccessService allowed direct WriteTable on it because the table is\nworkspace-capable. The embed\n[…]\ne()\nreturns false — i.e. anything not currently treated as embedded — so\nthe inline-related path stays in lockstep with read/write embedding.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Expose sys_file_metadata as a standalone editable table (#79)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-05-04T11:16:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e39454fbb05fdeb9986763e6c627ffb3fdf193ca",
          "body": "…e (#75)\n\n* fix(ReadTable): apply workspace overlay so workspace edits are visible\n\nWorkspaceRestriction strips workspace versions out of result sets and expects\nthe caller to fold them back in via BackendUtility::workspaceOL(). ReadTableTool\nnever did that, so a record changed in a workspace was re\n[…]\nfor the success path: the new flag is additive, and the\ncatch block only ever falls back to the row we already had pre-overlay.\n\n---------\n\nCo-authored-by: Thomas Schmidt <thomas.schmidt@contemas.net>",
          "is_bot": false,
          "headline": "fix(ReadTable): apply workspace overlay so workspace edits are visibl…",
          "author_name": "Thomas Schmidt",
          "author_login": "contemas-tschmidt",
          "committed_at": "2026-04-29T14:04:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0eefabef6d9e2a72e4402f4a8b042b9bc950bb25",
          "body": "The schema description for action=update already says 'omit to keep\ncurrent position, or specify to move the record', and updateRecord()\nalready routes a non-null position through moveRecord(). So far only\nposition=bottom on update was covered by tests; top, before:UID and\nafter:UID were not, leavin\n[…]\np, before:UID, after:UID, and a combined data + position update that\nboth renames and reorders a record in one call. No production change.\n\nCo-authored-by: Thomas Schmidt <thomas.schmidt@contemas.net>",
          "is_bot": false,
          "headline": "test(WriteTable): cover position=top/before/after on action=update (#77)",
          "author_name": "Thomas Schmidt",
          "author_login": "contemas-tschmidt",
          "committed_at": "2026-04-29T13:16:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9976a1b4a908a7bea7e38a75be4fda7f0cc44dcb",
          "body": "Inline children of hidden tables (sys_file_metadata, sys_file_reference,\ntx_news_domain_model_link, ...) used to carry every TCA-advertised column\ninto the response, including pid, tstamp, crdate, sys_language_uid,\nl10n_parent, l10n_diffsource, the foreign reference back to the parent,\nand TCA colum\n[…]\ning fields, drops the foreign_field that links\nback to the parent, and drops virtual TCA types. Top-level reads keep\ntheir existing behavior.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Filter plumbing fields from embedded inline children (#78)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-29T13:15:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "653212e07de3b73ea69ba9c98e8b11b02788e040",
          "body": "This change addresses three related inconsistencies that surfaced from real LLM use of the TYPO3 MCP server:\n\n1. **`sys_file` rows now carry `public_url`.** Previously, browsing fileadmin via `ReadTable` returned only an opaque `storage` uid + `identifier` pair, while embedded file references alread\n[…]\n by `getAvailableFields()` plus essential ctrl fields survive, and the computed-field bypass lives declaratively next to where each field is registered.\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Enrich sys_file rows with public_url and fix schema generation (#74)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-28T21:25:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7b395d880751c07380f973f834104c8c73a49dcb",
          "body": "…ler (#73)\n\nDataHandler treats type=imageManipulation as passthrough, so an array\nvalue (e.g. sys_file_reference.crop sent in the same shape ReadTableTool\nreturns) was cast to the literal string \"Array\" on the way into the DB.\nReadTableTool then failed to json_decode it and returned the string\n\"Arra\n[…]\n Add functional coverage for\nthe create/read and read-modify-write paths, including a sibling-only\nupdate that must leave the existing crop JSON intact.\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(WriteTable): json-encode imageManipulation values before DataHand…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-28T15:11:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2e46684c4e71eba8cf5d98f42706f99efc5fda7e",
          "body": "Tab headers were emitted unconditionally before processing fields, so\ntabs whose fields were all filtered out — or that had no fields at all\nin the TCA showitem (e.g. sys_file_metadata's \"Extended\" tab) — left\norphan headers in the rendered schema.\n\nBuffer the per-tab and per-palette field output and only emit the\nheader when there is at least one accessible child.\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(GetTableSchema): omit empty tabs from output (#72)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-28T15:10:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b4fe8f06cfdb6ae3e57cf72cb04afb42602d81ce",
          "body": "* fix(WriteTable): patch existing embedded inline relation by uid\n\nPayloads like `assets: [{uid: 42, title: \"patched\"}]` previously got\nre-routed through the create path, inserting a fresh sys_file_reference\nwith uid_local=0 instead of patching the existing one. The original\nreference stayed in the \n[…]\nclear the majority-pass threshold (4/5, 3/5, 5/5 models).\n\n---------\n\nCo-authored-by: Thomas Schmidt <backoffice@clicksgefuehle.at>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(WriteTable): patch existing embedded inline relation by uid (#64)",
          "author_name": "contemas-tschmidt",
          "author_login": "contemas-tschmidt",
          "committed_at": "2026-04-28T09:12:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "02fc68ecf22637b2d50cb20bc43c0cde30795e67",
          "body": "* e2e: add --no-docker mode using host PHP + SQLite\n\nThe Docker-based e2e flow assumes a working Docker daemon; some dev\nenvironments only have PHP + Node available. This adds a local fallback\nthat:\n\n- runs composer install on the host,\n- provisions TYPO3 against an SQLite database,\n- serves TYPO3 v\n[…]\ne:\nhost PHP 8.4 + SQLite + Playwright. Uploads playwright-report/test-results\nas an artifact when the job fails so failures are reproducible.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add --no-docker mode for E2E tests with local PHP and SQLite (#69)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-26T19:55:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ded409d3679ccb0e5f8a2dfa546bf387c7015b43",
          "body": "* Switch GPT model in LLM tests from gpt-5.4 to gpt-5.4-mini\n\nEvaluating whether the cheaper mini variant is viable now that we use\nreasoning.effort=high. Initial run: 13/24 pass (~54%); most failures\nare WriteTable(create) calls that omit record data entirely.\n\n* Always retry empty-data WriteTable \n[…]\n line, with the error count highlighted when non-zero — making it\nobvious which tests cost extra round-trips or recovered from tool\nfailures.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add LLM test statistics tracking and reporting (#67)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-26T14:39:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9e2a20ea958a6d45b43ccbce23c7c977a3cd635f",
          "body": "…et (#65)\n\nOn PRs from forks, GitHub does not pass repo secrets to workflow runs\nfor security reasons, so OPENROUTER_API_KEY is empty and every LLM\ntest calls markTestSkipped. The majority-pass check then exited 1\nbecause 0/5 < min-pass=3 — failing the PR for an environmental reason\nunrelated to the\n[…]\nce their actual code-level\ntest results without spurious red checks.\n\nCo-authored-by: Thomas Schmidt <backoffice@clicksgefuehle.at>\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(check-llm-results): treat all-skipped as neutral when no API key s…",
          "author_name": "contemas-tschmidt",
          "author_login": "contemas-tschmidt",
          "committed_at": "2026-04-23T14:35:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f1a47ab481112adbc0928d09571586f4db327410",
          "body": "* Add BeforeRecordWriteEvent, AfterRecordWriteEvent, ModifyAvailableFieldsEvent\n\nCherry-picked from #47 to give credit to the original author.\n\n* Wire up write/field events and add read events with sys_file listeners\n\nBuilds on the previous commit (which cherry-picked the three write/field\nevents fr\n[…]\n file_identifier, file_mime_type, file_size, and public_url to\n  sys_file_reference rows.\n\n---------\n\nCo-authored-by: Ingo Hollmann <hollmann@louis.info>\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Refactor record access control to event-driven architecture (#62)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-23T14:20:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "de9af1711a2f388134c6398c13d0d8b240028525",
          "body": "…#61)\n\nThe $restrictedTables blocklist was a leftover from when TableAccessService\nexposed non-workspace tables as read-only. With the current filters (TCA\nexistence, adminOnly, rootLevel, workspace-capable or additionalReadOnlyTables),\nevery entry in that list is already blocked earlier, so the har\n[…]\n- with getFieldRestrictions gone, the only remaining\n  message was \"Table is read-only\", which both consumers already render via\n  the read_only boolean\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: drop redundant restriction plumbing in TableAccessService (…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-23T14:17:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ce14268aa5551f0612715072b2e1c54c926525c2",
          "body": "Enables LLMs to read and write sys_file_reference as embedded relations on\ncontent elements, exposes sys_file as a read-only table with proper file-mount\npermissions, and replaces the hardcoded read-only allowlist with a configurable\nextension setting.\n\nCore functionality\n- Read/WriteTableTool handl\n[…]\neen pages preserving file refs,\n  fileadmin → sys_file discovery. Retry logic, turn budgets and final-state\n  assertions tuned for model variance.\n\nMisc\n- .gitignore: typo3temp and generated index.php",
          "is_bot": false,
          "headline": "Add file reference support to MCP tools (#53)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-22T21:15:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b8c81e9ab1c2140ddc0c627bcc8a2d35e68e43ee",
          "body": "…ool (#49)\n\nSearchTool pulled its candidate tables from getReadableTables(), which\nskipped the workspace-capability check and let search surface rows from\ntables that ReadTableTool would refuse (see issue #44). Switch to\ngetAccessibleTables(true) so both tools share one access set.\n\nRemove the escap\n[…]\ncentrally in one place, which is\nwhere future read-only / per-operation rules should also live.\n\nhttps://claude.ai/code/session_01YSaEtvQ2cLW9JPYUvaADAx\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: gate SearchTool on same workspace-capability check as ReadTableT…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-22T16:48:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9434953c843d6bf75866be44e8b0c713d58ff5d7",
          "body": "Run the LLM test suite across 5 models (haiku-4.5, gpt-5.4,\ngpt-oss-120b, mistral-large-2512, gemini-3-flash) using PHPUnit\ndata providers, and make results robust against the inherent\nnon-determinism of LLM responses.\n\nTest infrastructure\n- Add #[DataProvider('modelProvider')] and descriptive #[Tes\n[…]\nt with a\n  clearer prompt and proper position/sorting assertions.\n- Fix CI entry point path for LLM tests.\n- Add index.php and typo3temp/ to .gitignore.\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Refactor LLM tests with data providers and retry logic (#59)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-22T08:32:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f6ec41a67e5dd8e94cd6e9de1befb327b7e9ba46",
          "body": "…tTables (#35)\n\nGetTableSchemaTool:\n- Fix type parameter description: clarify it shows one type at a time,\n  not a summary. Document TSconfig-based type filtering.\n\nListTablesTool:\n- Fix false \"all workspace-capable\" claim — some tables are read-only\n- Update test assertions to match corrected output text\n\nCo-authored-by: Ingo Hollmann <hollmann@louis.info>",
          "is_bot": false,
          "headline": "fix: correct misleading schema descriptions in GetTableSchema and Lis…",
          "author_name": "Ingo Hollmann",
          "author_login": "BugHunter2k",
          "committed_at": "2026-04-21T18:54:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d5d3a2e1d483eafe10db551f4b73bf79edac601",
          "body": "* ci: drop root composer install from release-ter workflow\n\nThe release pipeline never reads the root vendor/ dir:\n- tailor runs from ~/.composer/vendor/bin (installed globally)\n- composer build:ter only needs composer.json to resolve the script\n- Build/build-ter.sh does its own composer install ins\n[…]\n vendor/ present\nproduces the zip successfully. Removing the step also removes the\n--no-dev/--no-scripts workaround from the previous commit.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Remove redundant Composer install step from release workflow (#55)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-20T14:11:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "15baf78880ef1629e1fce04e1f83df73e42d6cf7",
          "body": "…(#51)\n\n* Fix before:UID positioning using native DataHandler pid instead of broken move command\n\nThe before:UID position used a two-step approach: create at top of page, then\nmove via DataHandler cmdmap with an invalid array format. This caused the record\nto be placed at the top of the page instead\n[…]\no insert after it\n(= before the reference). When the reference is the first record, it inserts at\nthe top of the reference's page.\n\nFixes #50\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Improve content positioning logic for before/after element placement …",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-17T13:26:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "daa93af5d99497aa5016a6b3da35ceb554ccbc19",
          "body": "… (#52)\n\nToken-authenticated MCP requests bypass BackendUserAuthenticator middleware,\nso $beUser->userSession stays null. Any DataHandler UPDATE path that ends up\ncalling setAndSaveSessionData() (e.g. FlashMessageQueue, BackendFormProtection)\nthen fatals with \"Call to a member function set() on null\n[…]\nend — sufficient\nfor stateless MCP calls and fixes the crash without introducing persistence.\n\nAffects: every UPDATE operation via WriteTable tool.\n\nCo-authored-by: Ingo Hollmann <hollmann@louis.info>",
          "is_bot": false,
          "headline": "fix: init anonymous user session so DataHandler UPDATE does not crash…",
          "author_name": "Ingo Hollmann",
          "author_login": "BugHunter2k",
          "committed_at": "2026-04-17T13:18:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d86ab99ca30223f0d6999390e450149d21934c5",
          "body": "The publish_access field is a bitmask in TYPO3 where bit 0 (value 1)\nrestricts publishing to only content in the publish stage. Setting it\nto 1 (with the misleading comment \"Allow publishing\") was actually\nmore restrictive than the default and confused users familiar with\nthe TCA default of 0.\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: set publish_access to 0 when auto-creating MCP workspace (#48)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-13T15:36:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e12363ac99153c9fd62629fb922cc1d084e5f27a",
          "body": "…E tests (#46)\n\n* fix(security): hash OAuth tokens at rest with migration support\n\n- Store SHA-256 hash of access tokens in database instead of plain text\n- Add token_version column (0=plaintext, 1=hashed) for migration\n- Plain tokens returned to client at creation time but never persisted\n- Add ver\n[…]\ny token logic, update UI, and remove client-specific token handling.\n\n* fix: $GLOBALS['TYPO3_REQUEST'] is not available in middleware.\n\n---------\n\nCo-authored-by: Marco Pfeiffer <marco@hauptsache.net>",
          "is_bot": false,
          "headline": "fix(security): hash OAuth tokens, enforce PKCE S256, fix CORS, add E2…",
          "author_name": "Sebastian Mendel",
          "author_login": "CybotTM",
          "committed_at": "2026-04-10T09:20:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0fbab9f752d83f671cae54c8628c4852a3da4df",
          "body": "Use credentials: 'omit' instead of 'same-origin' in the backend module's\nauth header test fetch. When behind HTTP basic auth, 'same-origin' causes\nthe browser to send basic auth credentials which get replaced by the\nexplicit Bearer header, triggering a 401 from the web server and clearing\ncached credentials (logout).\n\nAlso normalizes CORS headers in handleAuthHeaderTest to use the shared\nCorsHeadersTrait instead of inline headers.\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix MCP test request logging out users behind HTTP basic auth (#43)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-07T19:42:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "057d0d7d6c29b4e12f1ebb92116ac9161fb5498c",
          "body": "* Fix GetPage URL resolution for URLs without protocol or trailing slash\n\nparse_url() treats \"www.example.com\" as a path (not a host), and\n\"https://example.com\" (no trailing slash) has no path key, causing\nthe fallback to use the full URL string as a path. This fixes both\ncases by:\n- Detecting domain-like inputs without a scheme and prepending https://\n- Defaulting to \"/\" when parse_url returns no path (instead of the raw URL)\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Improve URL resolution to handle domains without protocol (#42)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-04-07T19:32:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "af7233286db7c0bd4c0e1ca0e5e5a1894ac86c0d",
          "body": "* fix: align dependency constraints with TYPO3 v13\n\n- Raise PHP minimum to >=8.2 (TYPO3 v13 requirement)\n- Remove artificial PHP upper bound in composer.json\n- Set ext_emconf.php PHP to 8.2.0-8.99.99\n- Upgrade georgringer/news from ^12.0 to ^14.0 (PHP 8.4+ compat)\n- Fix ext_emconf.php version from 0\n[…]\n needed in\nthe TER release workflow. Install it globally there instead.\n\nSigned-off-by: Sebastian Mendel <info@sebastianmendel.de>\n\n---------\n\nSigned-off-by: Sebastian Mendel <info@sebastianmendel.de>",
          "is_bot": false,
          "headline": "chore: fix dependency constraints and TER workflow (#30)",
          "author_name": "Sebastian Mendel",
          "author_login": "CybotTM",
          "committed_at": "2026-04-01T09:48:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "570c29fc00ef877c812d42beba56935834df3423",
          "body": "McpEndpoint:\n- Add REDIRECT_HTTP_AUTHORIZATION fallback for Apache environments where\n  mod_rewrite or mod_auth_form strips the Authorization header and\n  re-exposes it with the REDIRECT_ prefix\n- Return RFC 9728 WWW-Authenticate header with resource_metadata URL\n  on 401 responses so MCP clients ca\n[…]\nsource/mcp as additional\n  resource metadata endpoint (referenced in WWW-Authenticate header)\n\nCo-authored-by: Ingo Hollmann <hollmann@louis.info>\nCo-authored-by: Marco Pfeiffer <marco@hauptsache.net>",
          "is_bot": false,
          "headline": "fix: improve auth header detection and OAuth discovery for Apache (#33)",
          "author_name": "Ingo Hollmann",
          "author_login": "BugHunter2k",
          "committed_at": "2026-04-01T08:52:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cee58bd0c950f12f54ed8189b1075cfbfbab755b",
          "body": "Tables like sys_file_reference use 'uid_local:type' as their ctrl.type,\nderiving the record type from a related record's field. This notation\nis not a local database column and caused SQL errors when passed to\nBackendUtility::getRecord() or used in field lookups.\n\ngetTypeFieldName() now returns null for foreign type notation (contains\n':'), treating these tables as typeless. getAvailableTypes() has an\nadditional guard as defense-in-depth.\n\nCo-authored-by: Ingo Hollmann <hollmann@louis.info>",
          "is_bot": false,
          "headline": "fix: handle foreign type notation in type field resolution (#32)",
          "author_name": "Ingo Hollmann",
          "author_login": "BugHunter2k",
          "committed_at": "2026-03-31T17:57:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17f6420a4326025f714d53c010344f1246589147",
          "body": "* fix: apply workspace overlays in GetPage and GetPageTree tools\n\nGetPageTool:\n- Apply BackendUtility::workspaceOL() to page and content records\n- Exclude records marked for deletion in the current workspace\n- Restore live UID after overlay for consistent API output\n- Prepend workspace context notic\n[…]\n per page record with deletion filtering\n- Prepend workspace mode notice to output\n\n---------\n\nCo-authored-by: Ingo Hollmann <hollmann@louis.info>\nCo-authored-by: Marco Pfeiffer <marco@hauptsache.net>",
          "is_bot": false,
          "headline": "fix: apply workspace overlays in GetPage and GetPageTree tools (#36)",
          "author_name": "Ingo Hollmann",
          "author_login": "BugHunter2k",
          "committed_at": "2026-03-29T14:30:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82e28ec512236bcd6856dab58c662b340c566a92",
          "body": null,
          "is_bot": false,
          "headline": "remove claude-code-review.yml, it didn't work too well.",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-03-27T16:28:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddbb919652646c7bace9df5ff1e30d533ee977b3",
          "body": "* Fix URL resolution failing for URLs with trailing slash\n\nStrip trailing slash from non-root paths before router and slug lookup,\nsince TYPO3 stores slugs without trailing slashes. Fixes #15.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix URL resolution to handle trailing slashes correctly (#28)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-03-19T09:07:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "af5837ce259bc8fa8fcc643ddb0204bd013e84eb",
          "body": "… position (#27)\n\n* Add failing test for sequential content element sorting (issue #26)\n\nReproduces the bug where creating multiple content elements sequentially\nwith position \"bottom\" results in reverse order. Elements created as\n\"1: First\", \"2: Second\", \"3: Third\" appear as \"3: Third\", \"2: Second\"\n[…]\nrdUid) to insert after the last record\non the page. Similarly, \"after:UID\" now uses negative pid directly instead\nof a separate move command.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix content element ordering when creating multiple records at bottom…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-03-18T16:42:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d306c49041c0f0741e3970c7f8f851d65aaaed50",
          "body": "* Fix MM relation updates on translations with allowLanguageSynchronization\n\nWhen updating MM relation fields (categories, tags) on translation records,\nTYPO3's DataHandler silently discards the values if the field has\nallowLanguageSynchronization enabled (l10n_state defaults to \"parent\").\n\nThe fix \n[…]\nords with MM relations (verifies copy behavior)\n- Overriding synced MM fields on translations\n- Combined workspace + translation MM scenarios\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Automatically set l10n_state to custom when updating translations (#21)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-03-16T15:12:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "689446718f8553d970c69da42d8aad2414cd1cf2",
          "body": "…ctively in use.",
          "is_bot": false,
          "headline": "Remove Work in Progress note. While true, this extension is already a…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-03-13T11:15:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5a346555d990053f254f6250a423b8d2328b54f",
          "body": null,
          "is_bot": false,
          "headline": "implement TER packaging and releasing",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-03-13T11:04:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e21a93a314b700c12a5268b8d017c23e17f49a7c",
          "body": "- Show info alert when no TYPO3 Workspace exists, recommending manual\n  creation for proper permissions/review workflow configuration\n- Detect localhost URLs and warn that remote MCP clients (Claude Desktop,\n  n8n, manus) cannot connect to localhost endpoints\n- Add per-client localhost warnings: dan\n[…]\nst MCP Inspector and TYPO3 CLI as working alternatives on localhost\n- Consolidate warnings above tabs and remove duplicated per-client alerts\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add workspace and localhost detection with improved warnings (#17)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-03-11T12:02:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "885467896c2923c5b7b6c6dad90761fcaa0c745e",
          "body": "* Add search_replace parameter to WriteTableTool for partial content updates\n\nLLMs updating large text fields (like bodytext with extensive HTML) previously\nhad to send the entire field value, wasting tokens and risking corruption.\n\nThe new search_replace parameter accepts targeted search-and-replac\n[…]\nptional replaceAll flag for intentional bulk replacements. The parameter is\nworkspace-aware, reading from workspace versions when they exist.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add search-and-replace support to WriteTable tool (#16)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-03-03T09:37:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "89995dd5d7a6fbf2dbd252cd30e11c73a9244a1b",
          "body": "…#13)\n\n* Add optional fields parameter to ReadTable tool for context reduction\n\nThe LLM can now specify which fields to include in the result, reducing\ntoken usage when only a subset of fields is needed. The filter respects\nTCA type-based field restrictions and field access control — it narrows\nresu\n[…]\ny. The uid is always included.\nEmbedded relations (e.g. sys_file_reference)\nare only resolved when their field name is in the requested list.\n\n---------\n\nCo-authored-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add fields parameter to ReadTableTool for selective field filtering (…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-02-22T13:55:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a5f814d766b5613d644e345bab5476663d014915",
          "body": "…6) (#11)\n\n* Strip trailing slashes from slug fields in WriteTable tool\n\nTYPO3's SlugNormalizer intentionally preserves trailing slashes present\nin the input, but trailing slashes in page slugs cause 404 errors in\nTYPO3's routing. The TYPO3 backend avoids this because its slug\nauto-generation flow never produces trailing slashes, but the MCP tool\nreceives slugs directly from LLM input and must sanitize them.\n\nFixes: #6",
          "is_bot": false,
          "headline": "Strip trailing slashes from slug fields in WriteTableTool (resolves #…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-02-22T12:01:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "005814ecdac8175b65472e8c57328c7fc58b8ee8",
          "body": "…771530602297\n\nAdd Claude Code GitHub Workflow",
          "is_bot": false,
          "headline": "Merge pull request #12 from hauptsacheNet/add-claude-github-actions-1…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-02-19T19:53:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "435e80c8c1c97a6d57c5a1a93726df9461794ccd",
          "body": null,
          "is_bot": false,
          "headline": "\"Claude Code Review workflow\"",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-02-19T19:50:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89431b4af979fabf000a8bd9f76ed5f79792e0e0",
          "body": null,
          "is_bot": false,
          "headline": "\"Claude PR Assistant workflow\"",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-02-19T19:50:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f5ce4ec3411089e9cb112c0d57d3cec092bf273",
          "body": "…assumptions-PM3TV\n\nfix: remove hardcoded sorting field name from WriteTableTool",
          "is_bot": false,
          "headline": "Merge pull request #10 from hauptsacheNet/claude/check-sorting-field-…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-02-16T15:54:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1950d49e5ed31b1da7351ea60d89b6bfffc7bff3",
          "body": "Some extensions (e.g. EXT:news) set sortby to empty string when manual\nsorting is disabled. The previous code returned '' which passed !== null\nchecks, causing SQL errors when trying to SELECT an empty column name.\n\nhttps://claude.ai/code/session_01WpBqLDhHAVcUD7qjSZxnjs",
          "is_bot": false,
          "headline": "Fix getSortingFieldName to return null for empty sortby values",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-02-13T10:02:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "199593947fb6c04c8161e4fe5c9ed707dc58fb57",
          "body": "The bottom position handling in WriteTableTool hardcoded 'sorting' as the\ncolumn name, causing SQL errors on tables that don't have a sorting field\n(e.g. tx_glossaries_domain_model_glossary). Now checks TCA configuration\nvia getSortingFieldName() and skips sorting entirely when no field is\nconfigured. Also uses the actual field name from TCA instead of hardcoding.\n\nhttps://claude.ai/code/session_01WpBqLDhHAVcUD7qjSZxnjs",
          "is_bot": false,
          "headline": "Fix sorting field assumption in WriteTableTool for tables without sortby",
          "author_name": "Claude",
          "author_login": "claude",
          "committed_at": "2026-02-13T09:39:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62fb863b5b870704e69846cc3c748f3adfc29955",
          "body": null,
          "is_bot": false,
          "headline": "implement proper version output",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-02-03T20:17:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79df22551ae43c2ee5f22d851459bd86cb65691b",
          "body": "Fix broken permissions when using a none-admin user (solves #5)",
          "is_bot": false,
          "headline": "Merge pull request #9 from hauptsacheNet/issue/5-none-admin-user-support",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-01-23T16:11:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5504b84b1b3836522827bc1e9c253da23d525196",
          "body": null,
          "is_bot": false,
          "headline": "#5 Improve model steering with the new permissions.",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-01-23T12:22:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7de2dc50e1d2b241027078d0642de9719d938cdc",
          "body": null,
          "is_bot": false,
          "headline": "#5 Load user group data to fix permission issue.",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-01-23T11:59:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57f0bf5ddd59c3435f4087a57e4f283ae137b326",
          "body": null,
          "is_bot": false,
          "headline": "Fix an issue where created pages in a workspace are not readable.",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-01-23T10:03:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2adcd3f790c42e66c42b015e9522b240d2f9fc61",
          "body": null,
          "is_bot": false,
          "headline": "remove redundant transport flag",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-01-11T16:45:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6cd9a09ce2008db8a6dff2ab52251d4d6bafd517",
          "body": "Use already existing tools for determing the sorting field in relations",
          "is_bot": false,
          "headline": "Merge pull request #8 from ischmittis/main",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2026-01-06T13:48:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f2ce68f497adcb6388dbdadca495798d3358c3f",
          "body": "…nal tables, fixed #7",
          "is_bot": false,
          "headline": "Use already existing tools for determing the sorting field in relatio…",
          "author_name": "Ingo Schmitt",
          "author_login": "ischmittis",
          "committed_at": "2026-01-06T09:43:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "553e4a9ad149801ac5141e75437055f55b340fbc",
          "body": null,
          "is_bot": false,
          "headline": "Add file field validation and update test",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-11-25T09:15:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a6e0517f5eb14f864a1c6edc3c79083ac54befe",
          "body": null,
          "is_bot": false,
          "headline": "use an enum for the schema tool (just like for Read/Write table)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-11-20T20:09:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84585fc0b0e1617b7f7d6dc7ac50184c5c474046",
          "body": null,
          "is_bot": false,
          "headline": "add very basic tsconfig filtering (addresses #4)",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-11-20T20:08:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "30f4b6a901af153c370727645eddaa6830c60e45",
          "body": null,
          "is_bot": false,
          "headline": "add the mcp inspector to the tool list",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-11-20T14:36:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e0564542a3ad641b6660d33e2bd378552fbf096",
          "body": null,
          "is_bot": false,
          "headline": "add instruction on how to setup manus and n8n",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-11-18T19:48:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d9f3c2420c4c0c111d3fa0c38e6d0f825837390",
          "body": "…f-the-box\n\nStabilize TYPO3 tests and add CI automation",
          "is_bot": false,
          "headline": "Merge pull request #3 from hauptsacheNet/codex/ensure-tests-run-out-o…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-09-20T17:00:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc4d0dc73f5a51307caa12510ae5d6f4bb28c976",
          "body": null,
          "is_bot": false,
          "headline": "CI: rely on composer hooks to bootstrap TYPO3",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-09-20T12:30:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c172200a334e2eb7dbaec4098b12c2c616b6822f",
          "body": "… implementation\n\n- Replace outdated TYPO3 `WorkspaceRestriction` details with a focused explanation of MCP-specific transparency handling.\n- Highlight custom restrictions, UID resolution, and query-time filtering for workspace operations in TYPO3.\n- Remove redundant background content to streamline the document and improve clarity for LLM-focused API use cases.",
          "is_bot": false,
          "headline": "refactor: rewrite workspace transparency documentation to clarify MCP…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-09-07T12:31:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f14d0609878b73b706ffbed296f6a2ec698582f",
          "body": "- Remove hardcoded development origins and fallback logic.\n- Default to returning `Origin` header when present or `*` for non-CORS requests.",
          "is_bot": false,
          "headline": "refactor: simplify CORS origin handling in CorsHeadersTrait",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-09-07T12:30:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "810f7f6eacdcf0f01ada463b3229187730c794c5",
          "body": "…s and tests\n\n- Eliminate redundant 'data' field in action payloads for 'create' and 'update' operations in WriteTableTool.\n- Adjust functional tests to reflect the updated payload structure and remove obsolete assertions.",
          "is_bot": false,
          "headline": "refactor: remove unnecessary 'data' field from WriteTableTool payload…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-30T10:59:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7d27fda548366451186e3f1824f656a6e5dc962",
          "body": "- Introduce `ExceptionHandlerTrait` in `AbstractTool` for consistent error handling across tools.\n- Replace individual `execute` methods with a templated `doExecute` pattern in all tools, ensuring uniform processing.\n- Standardize validation logic and replace inline error results with structured exc\n[…]\nGetPageTreeTool`, and `WriteTableTool` with refined validation, error messaging, and parameter handling.\n- Update functional tests to align with these refactored patterns and improve overall coverage.",
          "is_bot": false,
          "headline": "refactor: unify exception handling and streamline tool execution logic",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-27T14:08:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "47a5c2819f274ec657cad98d5a098f1bd4d68021",
          "body": "…ization\n\n- Adjust workspace creation logic in `WorkspaceContextService` to only include necessary fields.\n- Enable previously disabled plugin hint tests in `GetPageTreeToolPluginHintsTest`.\n- Extend depth limitation tests in `GetPageTreeToolTest` with comprehensive page structure and validation log\n[…]\nethods for test data creation and tree structure verification.\n- Refactor test cases in `ReadTableToolTest`, `SearchToolTest`, and `WriteTableToolTest` for improved readability and assertion handling.",
          "is_bot": false,
          "headline": "refactor: enhance functional testing and streamline workspace initial…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-27T12:22:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "91f1f1a94a114ca75a1ee2015ff61c21e5865111",
          "body": "…unctional tests\n\n- Add support for collecting and displaying record counts and plugin hints in the page tree output.\n- Include doktype labels for improved readability of page types.\n- Update `renderTextTree` to integrate new information into output formatting.\n- Introduce functional tests to validate enhanced page tree features, including plugin storage hints and record counting.\n- Refactor and extend test fixtures for comprehensive scenario coverage.",
          "is_bot": false,
          "headline": "feat: enhance GetPageTreeTool with record counts, plugin hints, and f…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-26T13:03:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b27c06461ea42f3ec81aa17439d0bf3e41be93b6",
          "body": "…leSchemaTool\n\n- Enhance GetTableSchemaTool to translate LLL keys in control fields using TableAccessService.\n- Introduce functional test to validate proper translation of LLL keys in table schema output.\n- Ensure tests verify absence of raw LLL keys and confirm translated values in schema results.",
          "is_bot": false,
          "headline": "feat: add LLL key translation support and functional tests for GetTab…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-26T13:02:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a7be33d4c9285acd309c4f3dbe42ac967eda8d8",
          "body": "- Add a dedicated section highlighting important considerations for CLI server usage.\n- Include details on memory usage concerns and the need for restarts after code changes.\n- Adjust styling for better content segmentation and readability.",
          "is_bot": false,
          "headline": "feat: enhance MCP CLI access documentation with new considerations",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-25T09:46:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6645343e56df023b759896880a06ce01402798ca",
          "body": "- Introduce `handleAuthHeaderTest` to validate Authorization header delivery via MCP endpoint.\n- Enhance template with endpoint status indicators and Authorization header warning messages.\n- Provide solutions for common Authorization header issues (e.g., Apache configuration, proxy settings) in module UI.",
          "is_bot": false,
          "headline": "feat: add Authorization header detection and endpoint test for MCP",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-25T09:19:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "123e7da544dfd0febe60b469cd7cf8e45cc3694b",
          "body": "… add project status table\n\n- Replace verbose feature descriptions with a concise project status table, highlighting readiness of core components.\n- Remove duplicated details about MCP usage, OAuth flow, and workspace safety features to streamline content.\n- Add notes encouraging user feedback and real-world testing contributions.",
          "is_bot": false,
          "headline": "chore: restructure README for clarity, remove redundant sections, and…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-23T23:25:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "391206c21161aea7a7270a9b56c64e5d7aa5880a",
          "body": "…roved assertions\n\n- Update `AnthropicClientTest` to convert empty arrays to objects for compatibility with the Anthropic API.\n- Refine `ContentElementTest` to allow both `create` and `update` actions, improving flexibility for content management scenarios.\n- Extend `NewsTest` to support multiple va\n[…]\nons of category handling, ensuring robust validation.\n- Improve `SeoMetaTest` to accept scenarios where no updates are needed if pages already have descriptions, validating LLM analysis appropriately.",
          "is_bot": false,
          "headline": "test: enhance LLM test coverage with flexible action handling and imp…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-23T16:49:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9948f21c98447305aa37c34b2ad759012461f0a7",
          "body": "- Replace `parameters` definition with `inputSchema` across all tools for consistency with MCP spec.\n- Introduce schema `annotations` to indicate read-only and idempotent property hints.\n- Remove redundant `getToolType` methods from tools as they are no longer required.\n- Simplify schema by removing examples deprecated from MCP specifications.\n- Update functional tests to align assertions with `inputSchema` usage.",
          "is_bot": false,
          "headline": "refactor: indicate read-only tools and simplify input schema",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-22T16:16:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5fd677203f8b537450684abdbcf65a4a1bf0d37",
          "body": "…iscovery\n\n- Include new CSS for endpoint status icons and tooltips.\n- Enhance template to display status indicators and tooltips for OAuth endpoints.\n- Add JavaScript to perform real-time endpoint availability and content validation checks.\n- Extend feedback to users with specific statuses: success, warning, error, or checking.",
          "is_bot": false,
          "headline": "feat: add endpoint status indicators and real-time checks for OAuth d…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-22T14:34:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "053f281c1996fe4618927b102d6a808fabdeeba4",
          "body": "- Update `createDirectAccessToken`, `validateToken`, and `exchangeCodeForToken` to accept `$request` explicitly.\n- Refactor client IP retrieval logic to handle optional `$request` gracefully.",
          "is_bot": false,
          "headline": "fix: remove none existing ServerRequest::fromGlobals",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-22T11:04:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1bb855c8450e481b8035fb6c2eb0991130e74cb",
          "body": "…e, and refine requirements\n\n- Add authors and homepage to `composer.json`.\n- Update `ext_emconf.php` with new author details, beta state, and adjust TYPO3/PHP version constraints.\n- Include GPL-2.0 license file.\n- Update README to reflect the adjusted TYPO3 requirement.",
          "is_bot": false,
          "headline": "feat: update composer and extension metadata, add GPL-2.0 license fil…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-22T11:01:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8cbf8f5d3c8978084a59240bf4ce5ee5d0e0027c",
          "body": "- Introduce `NewsTest` to validate LLM's ability to create and manage news content.\n- Add fixtures for pages (`news_pages.csv`), categories (`news_categories.csv`), and plugins (`news_plugin.csv`) to simulate content scenarios.\n- Cover scenarios including website launch announcements, product launches with category assignment, and news placement in the appropriate site section.",
          "is_bot": false,
          "headline": "test: add comprehensive tests for LLM news creation and management",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-22T10:37:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77e50281b0cb1e4fe061e6a7ab82e8e5a2bbe2ce",
          "body": "…ol and WriteTableTool\n\n- Include accessible tables in `enum` for `table` property in both Read and Write tools.\n- Ensure alphabetically sorted table names for better readability.\n- Enhance validation logic in `TableAccessService` to flag suspicious system tables with workspace support.",
          "is_bot": false,
          "headline": "feat: add accessible table enums to schema generation for ReadTableTo…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-21T16:41:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc7e203ec2f72b500cd04929ca7e438e8d7793e9",
          "body": "…tility and extend related functional tests\n\n- Enhance `TcaFormattingUtility` to detect and display richtext/HTML and typolink support in configurations.\n- Add detailed examples for typolinks in supported formats.\n- Introduce `GetTableSchemaNewsTest` functional test to validate richtext and typolink support in news schema.\n- Extend `GetTableSchemaToolTest` to cover richtext indicators and typolink examples in `tt_content` schemas.",
          "is_bot": false,
          "headline": "feat: add richtext and typolink support detection in TCA formatting u…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-21T15:49:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b943087edb494e808056f20e2774d5a85dfcf583",
          "body": "…areness\n\n- Add support for identifying and utilizing backend layouts in `GetPageTool`, including fallback mechanisms for parent or TSConfig-based layouts.\n- Introduce warning for content placed in undefined columns under custom layouts.\n- Enhance plugin detection to display name, configuration, and\n[…]\nate functional tests to cover various backend layout scenarios: database, inheritance, TSConfig, and default fallbacks.\n- Adjust test fixtures to include backend layouts and relevant content examples.",
          "is_bot": false,
          "headline": "feat: enhance `GetPageTool` with backend layout support and plugin aw…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-21T13:21:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82703e1eaec2850355cf3e503d66fb1803029014",
          "body": "- Add `WorkspaceContextService` to dynamically manage workspace context initialization and switching.\n- Replace hardcoded workspace IDs with dynamic retrieval for increased flexibility in tests.\n- Integrate `brianium/paratest` for faster parallel test execution.\n- Update test scripts in `composer.json` to utilize Paratest for functional and LLM tests.\n- Enhance functional tests with improved workspace initialization and dynamic context awareness.",
          "is_bot": false,
          "headline": "feat: improve workspace handling and automate Paratest integration",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-21T11:19:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f5661a322f14654f23ab7caa16420c32ef1b66c",
          "body": "…ction methods\n\n- Add new sections for \"What Can You Do?\" to highlight key AI assistant capabilities across content management, SEO, and productivity.\n- Reorganize OAuth and CLI connection methods for improved clarity, emphasizing OAuth as the recommended option.\n- Include links to expanded technical documentation and architecture guides for further learning.",
          "is_bot": false,
          "headline": "docs: expand README with detailed usage examples and reorganize conne…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-21T11:17:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a57a65f1a9c280cffdb11655e56cb59d14947a8",
          "body": "…nt element",
          "is_bot": false,
          "headline": "test: update `ContentElementTest` to not specify the CType of a conte…",
          "author_name": "Marco Pfeiffer",
          "author_login": "Nemo64",
          "committed_at": "2025-07-21T10:18:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 15,
      "commits_last_year": 81,
      "latest_release_at": "2026-06-22T09:28:09Z",
      "latest_release_tag": "v0.4.4",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 25,
      "days_since_latest_release": 35,
      "mean_days_between_releases": 12.3
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "hn/typo3-mcp-server",
          "exists": true,
          "license": "GPL-2.0-or-later",
          "keywords": [],
          "ecosystem": "packagist",
          "matches_repo": true,
          "registry_url": "https://packagist.org/packages/hn/typo3-mcp-server",
          "is_deprecated": false,
          "latest_version": "v0.4.4",
          "repository_url": "https://github.com/hauptsacheNet/typo3-mcp-server",
          "versions_count": 16,
          "total_downloads": 29978,
          "dependents_count": 1,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 7025,
          "first_published_at": null,
          "latest_published_at": "2026-06-22T09:22:54Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 35
        }
      ]
    },
    "popularity": {
      "forks": 21,
      "stars": 91,
      "watchers": 12,
      "fork_history": {
        "days": [
          {
            "date": "2025-11-08",
            "count": 1
          },
          {
            "date": "2026-01-06",
            "count": 1
          },
          {
            "date": "2026-01-19",
            "count": 2
          },
          {
            "date": "2026-01-29",
            "count": 1
          },
          {
            "date": "2026-02-09",
            "count": 1
          },
          {
            "date": "2026-03-02",
            "count": 1
          },
          {
            "date": "2026-03-09",
            "count": 1
          },
          {
            "date": "2026-03-13",
            "count": 2
          },
          {
            "date": "2026-03-16",
            "count": 1
          },
          {
            "date": "2026-03-19",
            "count": 2
          },
          {
            "date": "2026-03-25",
            "count": 1
          },
          {
            "date": "2026-04-21",
            "count": 2
          },
          {
            "date": "2026-06-17",
            "count": 1
          },
          {
            "date": "2026-06-24",
            "count": 1
          },
          {
            "date": "2026-06-26",
            "count": 2
          },
          {
            "date": "2026-07-21",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 21,
        "total_forks": 21
      },
      "star_history": null,
      "open_issues_and_prs": 19
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "Build/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 96854,
      "source_files_sampled": 155,
      "oversized_source_files": 2,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 1890
    },
    "dependencies": {
      "manifests": [
        "Build/package.json",
        "composer.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm",
        "packagist"
      ],
      "dependencies": [
        {
          "name": "logiscape/mcp-sdk-php",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^1.2"
        },
        {
          "name": "typo3/cms-backend",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^13.4 || ^14.3"
        },
        {
          "name": "typo3/cms-core",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^13.4 || ^14.3"
        },
        {
          "name": "typo3/cms-workspaces",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^13.4 || ^14.3"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 10,
        "merged_prs": 59,
        "open_issues": 9,
        "closed_ratio": 0.625,
        "closed_issues": 15,
        "closed_unmerged_prs": 11
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "Nemo64",
          "commits": 131,
          "avatar_url": "https://avatars.githubusercontent.com/u/1749936?v=4"
        },
        {
          "type": "User",
          "login": "BugHunter2k",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/5654631?v=4"
        },
        {
          "type": "User",
          "login": "contemas-tschmidt",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/14309291?v=4"
        },
        {
          "type": "User",
          "login": "claude",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
        },
        {
          "type": "User",
          "login": "konradmichalik",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/4558190?v=4"
        },
        {
          "type": "User",
          "login": "CybotTM",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/326348?v=4"
        },
        {
          "type": "User",
          "login": "ischmittis",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/904789?v=4"
        },
        {
          "type": "User",
          "login": "Tuurlijk",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/790979?v=4"
        }
      ],
      "contributors_sampled": 8,
      "top_contributor_share": 0.879
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "claude.yml",
        "release-ter.yml",
        "tests.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 1,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 7,
            "reason": "23 out of 30 merged PRs checked by a CI test -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 2,
            "reason": "Found 8/30 approved changesets -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 3 contributing companies or organizations -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "24 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "2cdc3f3cf8f7a256acd040f1abfe7e41fe49ee47",
        "ran_at": "2026-07-27T21:02:54Z",
        "aggregate_score": 4.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T20:46:04Z",
      "oldest_open_prs": [
        {
          "number": 20,
          "created_at": "2026-03-11T14:19:33Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 29,
          "created_at": "2026-03-19T21:48:13Z",
          "last_comment_at": "2026-06-24T16:13:59Z",
          "last_comment_author": "CybotTM"
        },
        {
          "number": 34,
          "created_at": "2026-03-25T10:02:55Z",
          "last_comment_at": "2026-03-25T10:03:02Z",
          "last_comment_author": "chatgpt-codex-connector"
        },
        {
          "number": 54,
          "created_at": "2026-04-17T13:45:05Z",
          "last_comment_at": "2026-04-17T13:45:10Z",
          "last_comment_author": "chatgpt-codex-connector"
        },
        {
          "number": 68,
          "created_at": "2026-04-23T14:12:44Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 76,
          "created_at": "2026-04-29T09:13:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 85,
          "created_at": "2026-05-08T15:06:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 99,
          "created_at": "2026-06-23T14:53:30Z",
          "last_comment_at": "2026-06-23T14:54:23Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 102,
          "created_at": "2026-07-06T10:07:23Z",
          "last_comment_at": "2026-07-06T10:07:49Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 103,
          "created_at": "2026-07-07T14:11:49Z",
          "last_comment_at": "2026-07-07T14:12:41Z",
          "last_comment_author": "coderabbitai"
        }
      ],
      "last_merged_pr_at": "2026-07-07T11:27:53Z",
      "ci_last_conclusion": "SKIPPED",
      "oldest_open_issues": [
        {
          "number": 2,
          "created_at": "2025-09-12T12:13:25Z",
          "last_comment_at": "2026-02-13T09:12:14Z",
          "last_comment_author": "oooFreaKooo"
        },
        {
          "number": 4,
          "created_at": "2025-11-18T19:58:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 40,
          "created_at": "2026-03-31T18:02:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 41,
          "created_at": "2026-04-05T18:57:41Z",
          "last_comment_at": "2026-04-13T09:36:38Z",
          "last_comment_author": "Nemo64"
        },
        {
          "number": 56,
          "created_at": "2026-04-20T13:16:31Z",
          "last_comment_at": "2026-07-07T07:39:35Z",
          "last_comment_author": "W4ldgeist"
        },
        {
          "number": 63,
          "created_at": "2026-04-23T11:40:55Z",
          "last_comment_at": "2026-04-26T13:55:59Z",
          "last_comment_author": "Nemo64"
        },
        {
          "number": 92,
          "created_at": "2026-05-14T11:08:32Z",
          "last_comment_at": "2026-05-18T15:47:06Z",
          "last_comment_author": "Nemo64"
        },
        {
          "number": 104,
          "created_at": "2026-07-27T17:55:03Z",
          "last_comment_at": "2026-07-27T20:14:02Z",
          "last_comment_author": "Epoche-Napoleon"
        },
        {
          "number": 105,
          "created_at": "2026-07-27T20:45:50Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/hauptsacheNet/typo3-mcp-server",
    "host": "github.com",
    "name": "typo3-mcp-server",
    "owner": "hauptsacheNet"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 64,
      "inputs": {
        "security": 46,
        "vitality": 84,
        "community": 50,
        "governance": 60,
        "engineering": 73
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 84,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "commits_last_year": 81,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 25
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "25/52 weeks with commits",
                "points": 17.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 25
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "81 commits in the last year",
                "points": 17.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 81
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "24 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 15,
              "latest_release_tag": "v0.4.4",
              "releases_from_tags": false,
              "days_since_latest_release": 35,
              "mean_days_between_releases": 12.3
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "15 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 15
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 35 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 35
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~12.3 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 12.3
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 20,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 20 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 20
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 50,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "forks": 21,
              "stars": 91,
              "watchers": 12,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "91 stars",
                "points": 31.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 91
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "21 forks",
                "points": 10.8,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 21
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "12 watchers",
                "points": 5.8,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (GPL-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "GPL-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": null,
            "notes": [],
            "value": 53,
            "inputs": {
              "packages": [
                "hn/typo3-mcp-server"
              ],
              "dependents": 1,
              "ecosystems": "packagist",
              "total_downloads": 29978,
              "monthly_downloads": 7025
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "7,025 downloads/month across packagist",
                "points": 51.3,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 7025,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "1 packages depend on it",
                "points": 2,
                "status": "partial",
                "details": [
                  {
                    "code": "registry_dependents",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 60,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 32,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 8,
              "top_contributor_share": 0.879
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 88% of commits",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 88
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "8 contributors",
                "points": 10.8,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "merged_prs": 59,
              "open_issues": 9,
              "closed_issues": 15,
              "issue_closed_ratio": 0.625,
              "closed_unmerged_prs": 11
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "62% of issues closed",
                "points": 29.2,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 62
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "59/70 decided PRs merged",
                "points": 32.2,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 59,
                      "decided": 70
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 8/30 approved changesets -- score normalized to 2",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "followers": 2,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "hauptsacheNet",
              "public_repos": 53,
              "account_age_days": 4724
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2 followers of hauptsacheNet",
                "points": 3.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2,
                      "login": "hauptsacheNet"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "53 public repos, account ~12 yr old",
                "points": 24.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 53
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 12
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "hn/typo3-mcp-server"
              ],
              "ecosystems": "packagist",
              "any_deprecated": false,
              "min_days_since_publish": 35
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on packagist",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 35 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 35
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "16 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 73,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "23 out of 30 merged PRs checked by a CI test -- score normalized to 7",
                "points": 14,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "mcp",
                "mcp-server",
                "typo3",
                "typo3-extension"
              ],
              "has_wiki": false,
              "homepage": "https://hauptsachenet.github.io/typo3-mcp-server/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://hauptsachenet.github.io/typo3-mcp-server/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "4 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 46,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 46,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "23 out of 30 merged PRs checked by a CI test -- score normalized to 7",
                "points": 1.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 8/30 approved changesets -- score normalized to 2",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "24 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 11
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 74,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.86,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 1890
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "86 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 86,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 63,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "Build/tsconfig.json"
              ],
              "agent_commit_share": 0.39,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Build/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Build/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "39 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 39,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "primary_language": "PHP",
              "largest_source_bytes": 96854,
              "source_files_sampled": 155,
              "oversized_source_files": 2
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "PHP with type-check config (Build/tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "Build/tsconfig.json",
                      "language": "PHP"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "2/155 source files over 60KB",
                "points": 54.3,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 155,
                      "oversized": 2
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T21:03:12.636791Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/h/hauptsacheNet/typo3-mcp-server.svg",
  "full_name": "hauptsacheNet/typo3-mcp-server",
  "license_state": "standard",
  "license_spdx": "GPL-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Packagist.