It also ships a clear README, license, and release notes for this version. For production, prefer the eventual stable 3.3 release over this release candidate.
82%
Total Score
100
100
93
67
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
This is a prerelease candidate, which adds some adoption risk, although it is within an established stable major line and recent prereleases represent only 20% of releases.
All seven workflows use unpinned actions, which weakens build reproducibility. However, six workflows use read-only permissions and the audit found no untrusted checkout, script injection, or other high-confidence findings.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-38145 silverstripe/versioned-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.0.0 - 1.11.1. | 1.0.0 - 1.11.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/admin Version ^3 | — | — |
silverstripe/framework Version ^6.2 | — | — |
silverstripe/versioned Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.