Recent releases and a clear README keep the package documented and established. One publisher, no security policy, and five unpinned workflow actions leave maintenance and build controls weaker.
67%
Total Score
50
100
94
75
Only one registry account has publishing access, leaving little visible publishing redundancy. The linked repository is also owned by an individual account, so no organizational backing compensates for the thin maintainer base.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization. This supports package identity but provides no evidence of broader project backing.
The repository recorded zero commits and zero active maintainers over the last three months. Although the release history is recent, this is direct evidence that source maintenance has currently stopped or slowed.
The repository has one open issue and one open pull request, but no issues or pull requests were created or closed in the last month. This is a modest sign of limited current activity.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a hygiene gap for a package handling authentication functionality.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/admin Version ^3.0 | — | — |
silverstripe/framework Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.