The package has clear documentation, tests, release notes, and organization backing. It lacks a security policy and scanning, while its workflow uses an unpinned action.
68%
Total Score
67
100
94
83
No commits and no active maintainers were recorded in the last 3 months. Combined with two releases in the last year, this indicates a small or currently paused maintenance effort and lowers confidence in rapid fixes.
There are only 2 open issues and no new or closed issues, pull requests, or merged pull requests in the last month. This is quiet rather than clearly abandoned, but it provides little evidence of active issue handling.
Composer is used for builds, but no security scanning tool was detected. The missing scanner is a meaningful hygiene gap for a dependency, though it is not evidence of unsafe code by itself.
The repository has no security policy. That leaves vulnerability reporting and response expectations unclear, which modestly reduces transparency.
The one workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings, and it has no broad top-level write permission. However, its single action use is unpinned, so the workflow has a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.