Clear licensing, a useful README, repository tests, and no install-time scripts support straightforward adoption. The small maintainer base and workflow pinning leave modest maintenance and build-hygiene concerns.
68%
Total Score
50
100
50
All recent commits came from one contributor, giving the project a complete short-term bus-factor concentration. The matching repository and package owner provide continuity but do not remove the succession risk.
The repository had 1 commit in the last 3 months from 1 active maintainer. Recent activity exists, but the low volume limits evidence of sustained maintenance capacity.
The repository has no security policy. For a small extension this is a transparency gap rather than a severe dependency risk, but it leaves vulnerability-reporting expectations unclear.
The sole workflow was fully analyzed with no audit findings or untrusted triggers, but both action references are unpinned. That creates a modest build reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^6 | — | — |
silverstripe/asset-admin Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.