The README is substantial, repository tests are present, and the release line is stable. Organization backing and frequent recent registry releases provide useful maintenance evidence, but workflow references are not pinned.
72%
Total Score
75
100
86
67
The artifact contains a license file and the repository also has one, but the detected MIT license does not match the manifest's BSD-3-Clause declaration. That inconsistency reduces transparency and merits verification before adoption.
The repository recorded zero commits and zero active maintainers in the last three months. Frequent registry releases partly offset this, but the lack of recent source activity is still a maintenance caution.
Composer is used as a build tool, but no security scanning tools were detected. The absence is a modest transparency and maintenance gap, not evidence of unsafe code by itself.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it does not by itself indicate abandonment.
The single workflow was fully analyzed with no reported audit findings or untrusted sinks, but all four action references are unpinned. That leaves avoidable supply-chain drift risk in CI.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/admin Version ^2 || ^3 | — | — |
silverstripe/framework Version ^5 || ^6 | — | — |
silverstripe/vendor-plugin Version ^2 || ^3 | — | — |
restruct/silverstripe-simpler Version ~0.2 || ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.