The license, documentation, release notes, and organization backing provide useful transparency. Workflow references are all unpinned, and recent repository activity has not translated into releases or commits, so maintenance continuity is uncertain.
62%
Total Score
67
83
The package has 51 releases over about 9 years, but no registry release in the last 12 months; the latest release was in November 2024. This materially weakens confidence in ongoing maintenance.
There were no commits and no active maintainers in the last 3 months. The repository's recent push timestamp is a compensating sign of activity, but the observed commit window still indicates uncertain maintenance continuity.
The repository has 18 open issues and 12 open pull requests, but no new or closed issues and no merged pull requests in the last month. This suggests limited recent issue-management activity.
Composer is used as a build tool, but no security-scanning tools were detected. The missing scanning layer is a modest transparency and hygiene concern, not evidence of abandonment by itself.
All 7 analyzed action references are unpinned, so workflow dependencies can change without a reviewed commit. The audit found no dangerous sinks, high-severity findings, or broad top-level write permissions, which keeps this at a hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.