The package has a clear README, a stable major version, and no install-time scripts. Its six runtime dependencies and single registry maintainer add upkeep burden, while the tiny repository has no tests or security scanning.
42%
Total Score
38
50
72
88
The latest release was nearly eight years ago, with three releases total and none in the last 12 months. This is strong evidence of abandonment risk for a package with ongoing framework dependencies.
There were no commits and no active maintainers in the last three months, consistent with the nearly eight-year-old last push. This materially raises abandonment risk.
The package declares six runtime dependencies, including the Silverstripe framework, CMS, and Mapbox modules. This creates meaningful compatibility and maintenance exposure for an otherwise inactive release.
Only one registry account has publish access. That is a thin publishing base for a personal project and increases continuity risk if the maintainer stops updating it.
The repository is owned by an individual account rather than an organization, and the registry namespace also identifies an individual. There is no organizational backing shown to compensate for the thin maintainer base.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version >=4.0 | — | — |
silverstripe/framework Version >=4.0 | — | — |
xddesigners/silverstripe-mapbox Version * | — | — |
symbiote/silverstripe-addressable Version * | — | — |
bramdeleeuw/silverstripe-pageslices Version >=2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.