Package Health

nswdpc/silverstripe-csp

SilverStripe Content Security Policy module

Latest v2.1.1PackagistPackagist

72%

Total Score

caution

Usable with caveats: all recent work comes from one contributor and workflow actions are unpinned.

Health Score Breakdown

Repo bus factorcaution

One contributor made all 30 commits in the last three months. Organization backing provides some handoff capacity, but no second active contributor is shown, leaving a real continuity risk.

Repo issue activitycaution

Seven issues remain open and there were no issues or pull requests opened or closed in the last month. Recent commit activity offsets this somewhat, but issue follow-through is not demonstrated.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.

Security policycaution

The repository has no security policy. For a module handling Content Security Policy and violation reports, the missing vulnerability-reporting guidance is a genuine transparency gap.

Workflow auditcaution

The workflow audit completed cleanly with no untrusted checkout, injection, or high-confidence audit findings, but both analyzed action references are unpinned. That leaves avoidable dependency-integrity risk in CI.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

James Ellis

Direct Dependencies

DependencyLast ReleaseScore
silverstripe/cms
Version ^6
—
—
silverstripe/framework
Version ^6.2
—
—
symbiote/silverstripe-queuedjobs
Version ^6
—
—
symbiote/silverstripe-multivaluefield
Version ^7
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform