The README is present and the dependency set is focused. Maintenance is active, but this is a brand-new release line with all recent commits from one contributor and a license mismatch in the artifact.
64%
Total Score
83
100
81
83
The manifest declares BSD-3-Clause, but the only detected license is MIT inside a vendored dependency, so the artifact's licensing is inconsistent despite containing a license file.
This package is newly published, with seven releases all appearing on the same day and no established release interval. The linked repository's recent activity provides some compensation, but release maturity is unproven.
All 70 recent commits came from one contributor. Organization backing offers some handoff capacity, but no second active contributor is shown, leaving maintenance continuity concentrated.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of unsafe code.
The repository has no security policy, leaving reporting and response expectations undocumented for a package handling consent-related site behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^4.0 | — | — |
silverstripe/admin Version ^1.0 | — | — |
silverstripe/framework Version ^4.0 | — | — |
silverstripe/siteconfig Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.