It has a focused dependency set, clear documentation, tests, and a matching source repository. Recent releases offset the quiet commit period, but the workflow's unpinned action and absent security tooling reduce confidence in ongoing maintenance hygiene.
68%
Total Score
50
100
94
83
The registry namespace and repository are owned by the same individual account, which is consistent with this small package but provides less organizational backing than a maintained organization-owned project.
There were no commits and no active maintainers in the last three months. The recent release history partly compensates, but the quiet source repository lowers confidence in ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance-hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy. For a small package this is a transparency gap, though it is not severe enough to outweigh the active release history and tests.
The workflow audit completed fully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, its only action reference is unpinned, leaving a modest reproducibility and workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/siteconfig Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.