Clear documentation, tests, licensing, and release notes make the package straightforward to evaluate and integrate. Maintenance is currently narrow, with one recent contributor and no repository security policy. The organization backing and recent releases reduce abandonment concerns.
76%
Total Score
67
100
94
75
All recent commit activity comes from one contributor, creating a narrow maintenance path; organization backing partly reduces the handoff risk.
Only one commit was recorded in the last 3 months, which is limited activity, although the recent release history provides some evidence that maintenance has not stopped.
Composer build tooling is present, but no security scanning tools were detected, leaving repository security checks less visible.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
The single workflow was fully analyzed with no audit findings or untrusted-code sinks. Its one action is unpinned, a minor reproducibility concern, while the absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.