The package is licensed, documented, and has a focused dependency set. Organization backing and read-only permissions in six workflows help, but the repository lacks a security policy.
70%
Total Score
67
100
100
50
One contributor made 100% of the single recent commit. Organization ownership provides some handoff capacity, but no second recently active contributor is shown, leaving current work concentrated.
Only 1 commit was recorded in the last 3 months, from 1 active maintainer. Despite the recent release history, this indicates thin current maintenance activity.
The repository has no security policy. For a module involved in CMS login screens, this is a meaningful transparency gap, although it does not by itself show unsafe code.
All 7 analyzed action references are unpinned, which weakens build reproducibility. The audit found no untrusted checkout or script-injection sink, and 6 workflows use read-only permissions, limiting the severity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.