Clear licensing, a useful README, and GitHub release notes make adoption easier. The project is backed by an organization, but workflow references are not pinned.
73%
Total Score
67
100
94
75
All recent commit activity came from one contributor, creating a narrow current maintenance base. Organization backing provides some handoff capacity, but no second active contributor is shown.
Only 1 commit was recorded in the last 3 months, which indicates limited recent development activity despite the recent release history.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All 7 workflows were analyzed with no audit findings, six use read-only permissions, and the pull_request_target trigger has no untrusted checkout or script-injection sink. However, all 7 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^6.2 | — | — |
silverstripe/asset-admin Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.