The artifact is licensed, documented, and has a small, focused dependency set. The linked project lacks a security policy and does not clearly identify this package, weakening transparency and confidence in ongoing support.
52%
Total Score
75
100
81
88
The package is 447 days old with 14 releases, but it has had no release in the last 12 months; that points to stalled maintenance for a dependency intended to track its ecosystem.
There were zero commits and zero active maintainers in the last three months, consistent with an inactive project and increasing abandonment risk.
The repository name does not match the package and its README does not mention the package, creating a concrete concern that the linked source may not clearly correspond to this release.
Composer is used for the build, but no security-scanning tooling was detected; this is a modest transparency and maintenance gap rather than evidence of a defect.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ~4.0 | — | — |
silverstripe/versioned Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.