It includes repository tests, a clear license, and two recently active contributors. The release is a release candidate, and all six workflow actions are unpinned, so a stable successor is preferable.
82%
Total Score
100
100
86
67
Composer build tooling is present. No security scanning tools were detected, which is a minor transparency gap but not a standalone dependency risk.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear. This is a modest transparency concern for a maintained framework component.
This release is a prerelease candidate, which adds some adoption risk compared with a stable release. Recent prereleases account for 35% of releases, so this is a modest concern rather than evidence of instability across the project.
All six workflows were analyzed with no audit findings, five use read-only permissions, and the pull_request_target workflow has no untrusted checkout or script-injection sink. All six action references are unpinned, creating a reproducibility and supply-chain hygiene gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-24749 silverstripe/assets is vulnerable to Incorrect Privilege Assignment in versions 0.0.0 - 2.4.5 and 3.0.0 - 3.1.3. | 0.0.0 - 2.4.53.0.0 - 3.1.3 | Medium |
CVE-2022-38724 silverstripe/assets is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.0.0 - 1.11.1. | 1.0.0 - 1.11.1 | Medium |
CVE-2022-38147 silverstripe/assets is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.0.0 - 1.11.1. | 1.0.0 - 1.11.1 | Medium |
CVE-2022-29858 silverstripe/assets is vulnerable to Improper Authentication in versions 1.0.0 - 1.10.1. | 1.0.0 - 1.10.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^7.0 | — | — |
league/flysystem Version ^3.29 | — | — |
intervention/image Version ^3.9 | — | — |
symfony/filesystem Version ^7.0 | — | — |
league/flysystem-local Version ^3.29 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.