Bigfork’s SilverStripe CMS recipe
64%
Total Score
caution
Usable with caveats: the only registry release is from 2019 and all five workflow actions are unpinned.
The recipe declares 14 runtime dependencies spanning the CMS, deployment-related functionality, monitoring, and extensions. That breadth is consistent with a project recipe but increases the maintenance surface for consumers.
This package has only one release, published about seven years ago, with no releases in the last 12 months. That weakens release transparency and raises the risk that this registry version is stale, although recent repository activity partly compensates.
Two contributors were active recently, with the top contributor responsible for 75% of commits. The second active contributor and organization ownership reduce, but do not eliminate, concentration risk.
Composer is used as the build tool, which fits the package ecosystem. No security scanning tool was detected, leaving a modest assurance gap.
The repository has no security policy. That reduces transparency about vulnerability reporting and response, although it is not evidence of a vulnerability itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sentry/sentry Version ^1 | — | — |
silverstripe/cms Version ^4 | — | — |
silverstripe/assets Version ^1 | — | — |
silverstripe/config Version ^1 | — | — |
kinglozzer/metatitle Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.