Enable multi-factor authentication with fallback codes
72%
Total Score
caution
Regular releases and organizational backing offset one-contributor activity and completely unpinned workflow actions.
One contributor made all commits in the last 3 months, giving the recent repository activity a single-contributor concentration. Organizational ownership provides some handoff capacity, but no second recent contributor is shown.
Only one commit was recorded in the last 3 months, indicating narrow recent development activity even though the package continues to release.
Composer is used for builds, but no security scanning tool was detected; this is a transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no security policy, leaving vulnerability reporting and handling expectations undocumented.
All 8 workflows were analyzed without audit findings or untrusted checkouts, and six use read-only permissions. However, all 7 analyzed action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/admin Version ^3 | — | — |
defuse/php-encryption Version ^2.4 | — | — |
silverstripe/framework Version ^6.1 | — | — |
silverstripe/siteconfig Version ^6 | — | — |
silverstripe/login-forms Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.