Package Health

cyber-duck/silverstripe-seo

Documentation, tests, changelog, and release notes are present, and the repository clearly belongs to the package. Organization backing and a recent repository push help, but inactive issue and commit activity, no security policy, and a license mismatch reduce confidence.

Latest 4.6.2PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

The artifact includes license files and the repository has a license file, but the manifest declares MIT while the detected license is BSD-2-Clause. The mismatch reduces transparency despite the release being licensed.

Release historycaution

The package has 29 releases over more than 10 years, but no registry releases in the last four years; this indicates a materially slowing maintenance cadence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. Although it was pushed in September 2024, current development activity is inactive.

Repo issue activitycaution

There are open issues and pull requests, but none were opened, closed, or merged during the last month. This suggests limited current responsiveness.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest supply-chain hygiene gap, not evidence of unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andrew Mc Cormack

Direct Dependencies

DependencyLast ReleaseScore
silverstripe/cms
Version ^4.0
silverstripe/framework
Version ^4.0

Weekly Downloads

Info

Last Published
4 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform