The repository matches the package, includes a usable README, and has no install scripts. Its small scope limits complexity, but there is no security policy and no recent development evidence.
43%
Total Score
25
75
75
Only two releases were published, both on January 29, 2021, with none in the last five years. This is strong evidence of abandonment risk for a dependency, despite the package remaining undeprecated.
The repository had zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but it shows no current maintenance activity.
The registry lists one maintainer, which provides limited publishing redundancy. The package is small and its repository is owned by the matching publisher, partly reducing the concern.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, although the package is small and has no observed workflow automation.
The latest version is v1.0.1-beta and all recent releases are prereleases. That leaves consumers without a clearly stable release to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^4.0 | — | — |
silverstripe/vendor-plugin Version ^1.0 | — | — |
dnadesign/silverstripe-elemental Version ^3.0 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.