Clear licensing, tests, release notes, and organization backing support adoption. Recent inactivity, absent security scanning, and fully unpinned workflow actions leave meaningful maintenance and build-integrity concerns.
67%
Total Score
75
100
88
50
The package has existed since 2014 with 50 releases, but only one release occurred in the last 12 months, indicating a slower current cadence than its historical median of about 28 days.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful current-maintenance concern even though a recent release exists.
There are only three open issues and no open pull requests, with no issue or pull-request activity in the last month; this is a mild sign of limited current engagement.
Composer build tooling is present, but no security-scanning tools were detected, leaving a transparency and vulnerability-detection gap.
The repository has no security policy, so it provides no documented path for reporting vulnerabilities or describing security handling.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-24444 silverstripe/hybridsessions is vulnerable to Session Fixation in versions 1.0.0 - 2.4.1 and 2.5.0 - 2.5.1. | 1.0.0 - 2.4.12.5.0 - 2.5.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.