Package Health

wedevelopnl/silverstripe-svg-image

The package has repository tests, release notes, a clear license, and no install-time scripts. Its three workflow actions are unpinned and no security policy or scanning is reported, though job-level permissions and a complete audit reduce the concern.

Latest 2.1.1PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo toolingcaution

The project uses Make and Composer, but no security scanning tools are reported. This is a modest transparency and maintenance gap rather than evidence of abandonment.

Security policycaution

The repository has no security policy. For a module that sanitizes uploaded SVG files, the absence of a documented vulnerability-reporting process is a meaningful, though not severe, gap.

Workflow auditcaution

All workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings, and jobs scope permissions. However, all 3 action references are unpinned, leaving a reproducibility and action-integrity hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

WeDevelop

Direct Dependencies

DependencyLast ReleaseScore
meyfa/php-svg
Version ^0.14.5
—
—
enshrined/svg-sanitize
Version ^0.22
—
—
silverstripe/framework
Version ^5 || ^6
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform