The release is clearly documented, tested in its repository, and backed by a consistent release process. Recent repository activity is concentrated in one contributor, and all seven workflow actions are unpinned, which leaves avoidable maintenance and build-integrity concerns.
78%
Total Score
75
100
94
67
All recent commits came from one contributor, creating a narrow recent activity base. Organization backing partly compensates, but no second active contributor is shown for this period.
Only one commit was recorded in the last three months, so direct repository activity is currently light even though the package release history remains active.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and assurance gap.
The repository has no security policy, making vulnerability-reporting expectations less explicit for users and maintainers.
All eight workflows were analyzed successfully with no detected audit findings, no untrusted checkout or script-injection paths, and read-only permissions in six workflows. However, all seven action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/admin Version ^3 | — | — |
silverstripe/framework Version ^6.1 | — | — |
symfony/http-foundation Version ^7.0 | — | — |
donatj/phpuseragentparser Version ^1.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.