It includes tests, a changelog, clear licensing, and no install-time scripts. The beta release and unpinned workflow actions add avoidable risk, while recent releases and organization backing support continued maintenance.
82%
Total Score
88
88
67
Only two commits were recorded in the last three months, which is modest activity, but the repository was pushed recently and other activity shows ongoing maintenance.
The repository uses Composer build tooling, but no security scanning tools were detected. This is a transparency and maintenance-hygiene gap rather than evidence of an unsafe release.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This lowers transparency but is not by itself evidence of abandonment.
This release is a beta while the latest listed version is stable 1.1.3, so consumers should expect more change than with a stable release. The recent prerelease share is notable but does not indicate abandonment.
All seven analyzed action references are unpinned, which weakens build reproducibility. The audit found no untrusted checkout, script injection, high-severity issue, or broad top-level write permissions, and all workflows were analyzed successfully.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.