Skip to content
TYPO3Dev Companion
for security, data protection and procurement

It reads four things and sends one

You can check every claim on this page against the source, which is the whole argument for an open tool. What follows is the boundary, the history, and the way to tell us we got it wrong.

Report something you found

A named team reads this address, acknowledges inside one working day and agrees a disclosure date with you. We do not ask for silence beyond the fix, and we credit you unless you ask us not to.

1 working day 90 days
/.well-known/security.txt
text
Contact: mailto:security@example.org
Encryption: https://example.org/pgp-key.txt
Preferred-Languages: en, de
Policy: https://example.org/security
Expires: 2027-08-15T00:00:00.000Z

Its reach

Three things, and one of them leaves the machine. Stated as a table rather than as prose, because this is the section somebody copies into a procurement questionnaire.

What it touches Access When What survives
your project directory read while a tool answers nothing
the bundled index read always available ships with the release
docs.typo3.org one host, read only on a call to that tool nothing

Read means read: the process has no write path into your tree, which is checkable in the source rather than promised here. The bundled index comes from public sources once per release and is the only thing that answers when nothing else is reachable — and it says so in the answer. A single tool fetches the one host, only when that tool is the one called.

Nothing survives between runs: no account, no log of the questions, no cache of your project. This is why there is nothing here to export and nothing to delete — the process ends and takes its memory with it.

The one line that leaves

Drawn rather than described, because “it only calls out for documentation” is the kind of sentence a reader has to take on trust. The single outbound path is the exception in the picture, and it only reads.

There is no telemetry to turn off
No usage reporting, no crash reporting, no update check. A setting to disable one of those would imply there was one — so instead this says there is not.
Five sources feeding the server, with one arrow leaving the machine towards the documentation
Five sources, four of them on your disk. The one that leaves is drawn as the exception it is.
Five sources, four of them on your disk. The one that leaves is drawn as the exception it is.
Five sources feeding the server, with one arrow leaving the machine towards the documentation

Every advisory, including the slow one

Three so far, with the time from report to fix beside each. The nine days on the first one is in the table for the same reason the other two are: a history with the bad entry taken out is not a history.

Advisory Affects Fixed in Reported to fixed Severity
SA-2026-003 1.3.0 – 1.3.2 1.3.3 4 days low
SA-2026-002 1.2.0 – 1.2.4 1.2.5 2 days moderate
SA-2025-001 1.0.0 – 1.1.1 1.1.2 9 days high

An advisory comes out after a fix is available and never before. Every one of them names the versions affected rather than the ones fixed, because a reader checks what they run.

For the questionnaire

The four answers procurement asks for, given here rather than in a form somebody has to request. None of them changes per customer, which is why none of them is behind a contact form.

hosting
There is none

The tool runs as a subprocess of your editor, on your machine. There is no service to host, no region to choose and no subprocessor to name.

personal data
None is processed

It reads code and package metadata. Where a project’s own files contain personal data, they are read and not retained — nothing is written and nothing is sent.

retention
Nothing survives

No state survives the process. There is no log of the questions, which is also why we cannot produce one for an audit.

licence
MIT, and it stays MIT

The published source is the source that runs. There is no separate build for anyone, and no clause that changes for a paying reader.