The README is clear, the repository matches the package, and the BSD-3-Clause license plus lack of install scripts reduce adoption friction. Its SilverStripe 3.x target is old, and the repository has no security policy or scanning coverage.
43%
Total Score
25
71
75
The package has had only 3 releases since September 2016, with no release in more than 8 years and none in the last 12 months. This is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and leaving compatibility issues unlikely to be addressed.
Only one registry maintainer is listed. A single maintainer can be sufficient for a small package, but combined with the absence of recent activity it increases continuity risk.
Composer build tooling is present, but no security scanning tools are configured. This is a transparency and maintenance gap, though it is less significant than the inactivity evidence.
The repository has no security policy, so users are given no documented reporting or response process for vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^3.2 | — | — |
composer/installers Version * | — | — |
silverstripe/framework Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.