The package is licensed, documented, tested in its repository, and backed by an organization. Recent maintenance is quiet, with no commits or issue activity for three months. One workflow dependency is unpinned and no security policy is provided.
68%
Total Score
67
50
88
67
The package declares six runtime dependencies and two development dependencies. This is a meaningful integration surface, but not by itself evidence of abandonment or unsafe maintenance.
The package has existed since 2013 with 36 releases and a median release interval of about 63 days, but only one release occurred in the last 12 months. The long history compensates partly for the currently slow cadence.
The repository recorded zero commits and zero active maintainers in the last three months. This is the clearest current maintenance concern, although a release was published in February 2026.
There are 27 open issues and five open pull requests, with no new or closed issues or pull requests in the last month. The unresolved queue and lack of recent issue activity suggest limited responsiveness.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence that the release is unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/lumberjack Version ^3.0 | — | — |
silverstripe/recipe-cms Version ^5.0 | — | — |
dynamic/silverstripe-geocoder Version ^3.0 | — | — |
colymba/gridfield-bulk-editing-tools Version ^4.0 || ^5.0 | — | — |
littlegiant/silverstripe-catalogmanager Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.