Healthy and suitable to use, with a small maintenance caveat. It has a long release history, seven releases in the last year, a current unarchived repository, clear documentation, and organization backing; recent repository activity is limited to one contributor and one commit in three months.
78%
Total Score
63
94
80
All recent commits came from one contributor, creating concentration risk. The organization-owned repository provides some ability to hand maintenance off, so this is a caution rather than a severe abandonment signal.
The repository recorded one commit from one active maintainer in the last three months, showing some recent maintenance but at a low pace.
Only one issue is open and there are no open pull requests, but there was no issue or pull-request activity in the last month; this is a minor transparency and responsiveness concern for a small project.
Composer build tooling is present, but no security scanning tools were detected; this is a modest process gap rather than evidence that the package is unsafe.
The repository has no SECURITY.md policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/vendor-plugin Version ^3 | — | — |
dnadesign/silverstripe-elemental Version ^6 | — | — |
dynamic/silverstripe-elemental-baseobject Version ^6 | — | — |
symbiote/silverstripe-gridfieldextensions Version ^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.