Clear documentation, a changelog, a matching repository, and a simple dependency profile reduce adoption friction. Long-term support and security response are less certain, so pin this version if you adopt it.
65%
Total Score
50
100
88
88
Only one registry account has publish access, which leaves little publishing redundancy. The matching user-owned repository and recent release provide some compensation, but the release process still has a thin apparent base.
The registry namespace and repository are owned by the same individual, and the repository owner is identified as a user rather than an organization. This gives clear ownership but limited evidence of organizational support.
The package has existed since 2016 with 12 releases, but it has had no release in the last 12 months. That suggests slowing maintenance rather than abandonment by itself.
There were no commits and no active maintainers in the last three months. Although the repository was pushed with the latest release, the recent inactivity lowers confidence in ongoing fixes and compatibility work.
Composer build tooling is present, but no security scanning tools were detected. That is a modest transparency and maintenance gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.