The repository is identifiable, licensed, and still unarchived, with a matching README and no install-time scripts. The release is over six years old, with no recent registry releases and no commits in the last three months, so maintenance confidence is limited.
52%
Total Score
50
100
83
83
The package and repository are owned by the same individual account rather than an organization, so there is no visible organizational backing to compensate for the thin maintenance evidence.
The package has had no release in over six years and none in the last 12 months, which is a substantial maintenance concern, although the repository was pushed more recently than the release history suggests.
There were zero commits and zero active maintainers in the last three months, so current maintenance capacity is not demonstrated.
The repository has one star, zero forks, and one watcher, indicating very limited adoption; this is supporting caution rather than proof of poor quality.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest security-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^4.0@dev | — | — |
silverware/colorpicker Version ^1.0 | — | — |
silverstripe/vendor-plugin Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.