This release is generally usable, with a long package history, a stable non-prerelease version, an active non-archived organization-owned repository, matching package/source identity, repository tests and documentation, and no install-time lifecycle scripts. However, recent commit activity is absent despite the latest release and repository push, the project has very low adoption indicators, and it lacks both security scanning and a security policy. These concerns make the package suitable with normal dependency review and monitoring, but not as a fully mature, low-maintenance-risk dependency.
72%
Total Score
88
50
89
83
Six runtime dependencies create a meaningful dependency surface for a file-upload package, but the profile is not unusually large and no other signal indicates problematic dependency behavior.
There were 0 commits and 0 active maintainers during the last 3 months. Although the repository was pushed recently and the release is current, the absence of sustained commit activity is a meaningful maintenance warning.
The repository has only 2 stars and 4 forks, indicating limited visible adoption. Popularity is supporting evidence rather than a verdict, so this lowers confidence in maturity but is not by itself a severe risk.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning reduces supply-chain maintenance transparency without independently making the package unfit.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap for a package handling uploads.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/userforms Version ^6 | — | — |
silverstripe/asset-admin Version ^2 | — | — |
silverstripe/mimevalidator Version ^3 | — | — |
symbiote/silverstripe-multivaluefield Version ^6 | — | — |
nswdpc/silverstripe-filetype-management Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.