Tests, release notes, a license file, and organization backing improve confidence. The release metadata is inconsistent and the repository has no security policy, so pinning this candidate needs care.
69%
Total Score
75
93
67
The repository records zero commits and zero active maintainers in the last three months. This is a meaningful recent-maintenance gap, although the July 2026 release shows some compensating activity.
The repository has no security policy. That weakens disclosure transparency, though it is a moderate governance gap rather than evidence that the package is unfit to use.
The assessed version is 6.0.0-RC3, while the indicator reports latest_version 4.0.1 and says the release is not a prerelease. That inconsistency makes version maturity and registry metadata harder to trust.
All five analyzed action references are unpinned, which leaves workflow dependencies exposed to upstream changes. The audit found no dangerous triggers, untrusted checkouts, script injection, or high-confidence security findings, and job-level permissions are used.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
embed/embed Version ^4.0 | — | — |
silverstripe/cms Version ^6 | — | — |
silverstripe/asset-admin Version ^3.0 | — | — |
unclecheese/display-logic Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.