Usable with caveats: the package is clearly licensed, documented, and backed by a matching organization repository, but it has had only one release, in 2016, and no recent commit activity. Depend on it only if its old SilverStripe integration remains suitable for your project.
55%
Total Score
50
100
81
50
There has been only one release, published about 9 years ago, with no releases in the last 12 months. This is a substantial maintenance and compatibility concern for a dependency.
The repository had zero commits and zero active maintainers in the last 3 months. Combined with the old release history, this indicates a meaningful risk of abandonment or unaddressed compatibility issues.
There are no open issues or pull requests and no recent issue or pull-request activity. This is not inherently unhealthy, but it provides little evidence of ongoing maintenance.
The repository uses Composer, confirming basic build tooling, but has no security scanning tools. For this small package the missing scanning is a transparency gap rather than a severe risk.
The repository has no security policy. This limits the documented process for reporting vulnerabilities, though the package's small scope and lack of active workflows reduce the immediate significance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
undefinedoffset/sortablegridfield Version 0.6.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.