The package is licensed and tied to an organization-owned repository, with no install-time scripts or registry deprecation. Its tiny footprint and missing security tooling leave little evidence that it is ready for production use.
35%
Total Score
50
69
75
This is the package's only release, published about eight years ago, with no releases in the last 12 months. That leaves substantial abandonment and compatibility risk.
The repository has recorded no commits or active maintainers in the last three months, and its last push was in 2018. This strongly limits confidence that defects or compatibility issues will be addressed.
The artifact includes a README and release notes, but the notes explicitly say it is not production ready and invite work toward 1.0.0. The absence of tests is normal for a published artifact, so it is not treated as a separate gap.
Composer is used for the build, but no security-scanning tooling was detected. This is a transparency and maintenance gap, though it is less serious than the lack of recent development.
The linked repository has no security policy, so consumers have no documented reporting process. This lowers transparency but does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.