Clear licensing, release notes, and a readable package tree make adoption straightforward. The repository has no security policy, no security scanning, and all three recent commits came from one contributor.
74%
Total Score
67
100
93
75
The source repository is owned by a user account rather than an organization, so there is no provided organization backing to offset the concentrated recent contribution pattern.
All 3 recent commits came from one contributor, giving the project a top-contributor share of 100%. With a user-owned repository and no second active contributor shown, continuity depends heavily on one person.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest security-hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy. That leaves vulnerability reporting and response expectations unclear for consumers of this integration.
Both workflows were analyzed successfully with no high- or medium-confidence audit findings, untrusted checkouts, or script injection. However, one workflow has top-level write permissions and its one action use is unpinned, so workflow hygiene is not perfect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^6 | — | — |
guzzlehttp/guzzle Version ^7.5 | — | — |
silverstripe/vendor-plugin Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.