Documentation and packaging are in good shape, with tests, a README, and release notes. The small maintainer base and limited recent activity leave more continuity risk than a mature project.
72%
Total Score
50
100
50
Only one registry account has publishing access. That is a thin publishing base, although the repository and registry use the same owner.
One contributor made all two commits in the last three months, leaving no demonstrated recent contributor redundancy.
Only two commits were made in the last three months, which shows some maintenance but is a limited recent activity level for a dependency.
The repository has no security policy, reducing transparency around vulnerability reporting and maintainer response expectations.
The single workflow uses read-only permissions and has no audited findings or untrusted checkout sinks, but its one action reference is unpinned, leaving a modest build-integrity hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/recipe-core Version ^5 | — | — |
silverstripe/recipe-plugin Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.