The package has tests, a changelog, and a useful README, with no install-time scripts. The BSD/MIT licensing mismatch and repository naming mismatch add transparency concerns, while maintenance appears effectively stopped.
38%
Total Score
50
75
100
The package declares BSD and includes a license file, but the detected MIT license belongs to a bundled CodeMirror component. This mismatch warrants checking licensing boundaries before adoption.
The latest release was over 10 years ago, with no releases in the last 12 months. That strongly increases abandonment risk despite a history of six releases.
The repository had zero commits and zero active maintainers in the last three months, consistent with the package's long release gap and indicating no current maintenance capacity.
The linked repository name does not match the package name and its README does not mention the package, creating uncertainty about whether it is the intended source repository.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version >=3.1 | — | — |
composer/installers Version >=1.0 | — | — |
silverstripe/framework Version >=3.1 | — | — |
micschk/silverstripe-excludechildren Version 1.1.*@stable | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.