Documentation and packaging are adequate, and the dependency set is small. The project has little recent development activity, while repository naming and README references do not clearly connect it to this package.
61%
Total Score
75
100
81
75
The package has existed since 2018 but has only seven releases, with roughly 14 months between releases and one release in the last 12 months. This suggests a slow maintenance cadence, though the October 2025 release shows it is not abandoned outright.
There were no commits and no active maintainers in the last three months. That is a meaningful maintenance concern for a package intended to track framework compatibility.
The repository name does not match the package name and its README does not mention this package. Although the organization ownership provides some context, the weak repository-to-package linkage reduces transparency.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and assurance gap, not evidence of unsafe code.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^6 | — | — |
silverstripe/vendor-plugin Version ^3 | — | — |
dnadesign/silverstripe-elemental Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.