Clear licensing, tests, release notes, and a long release history add useful transparency. The repository is backed by an organization, but recent work is sparse and concentrated in one contributor; pinning workflows would improve build hygiene.
72%
Total Score
67
94
50
All recent commits came from one contributor, creating concentration risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only 2 commits were recorded in the last 3 months, with one active maintainer; this is weaker current maintenance than the release history suggests.
Composer build tooling is present, but no security scanning tools were detected, leaving a transparency and maintenance-hygiene gap.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
All 7 analyzed action references are unpinned, which weakens build reproducibility and action supply-chain hygiene. The audit found no untrusted checkout, script injection, excessive top-level write permissions, or other reported findings.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-25197 dnadesign/silverstripe-elemental is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.1.2 - 5.3.12. | 2.1.2 - 5.3.12 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^6 | — | — |
silverstripe/admin Version ^3.2 | — | — |
silverstripe/framework Version ^6.2 | — | — |
silverstripe/versioned Version ^3 | — | — |
silverstripe/versioned-admin Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.