The project has a long release history, regular recent releases, and organizational backing. Workflow permissions are mostly constrained, but action references are unpinned and no security policy is present.
68%
Total Score
67
88
50
One contributor made 100% of the last three months' commits. Organizational backing reduces the handoff concern somewhat, but recent activity remains highly concentrated.
Only 3 commits were made in the last 3 months, all by one active maintainer; this shows some maintenance but leaves limited recent contributor depth.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and supply-chain hygiene gap.
The repository has no security policy, which makes reporting and handling vulnerabilities less transparent for adopters.
This is a release candidate, and 70% of recent releases are prereleases, so consumers may face more change than with a stable release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/assets Version ~3.3.0@rc | — | — |
silverstripe/config Version ~3.1.0@stable | — | — |
silverstripe/framework Version ~6.3.0@rc | — | — |
silverstripe/mimevalidator Version ~4.0.0@stable | — | — |
silverstripe/recipe-plugin Version ~2.1.0@stable | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.