Usable with caveats: the package is established, licensed, documented, and not deprecated or archived, but maintenance appears to have stalled, with no releases in over a year and no commits in the last three months. Its small user and contributor footprint and lack of security scanning add modest risk.
62%
Total Score
67
88
88
The package has been maintained since 2017 with 23 releases, but it has had no release in the last 12 months, indicating a meaningful slowdown in maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, which is a concrete sign that maintenance may have stalled.
There are no open issues or pull requests, and no recent issue or pull-request activity. This may reflect stability, but it also provides no evidence of ongoing project response.
Composer build tooling is present, but no security scanning tools are configured, leaving a transparency and maintenance-process gap.
The repository has no security policy, so there is no documented path for reporting vulnerabilities or describing security response practices.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.