It has a clear README, matching repository, BSD-3-Clause license, and only one runtime dependency. Its small scope may limit maintenance needs, but ongoing compatibility is not demonstrated.
55%
Total Score
50
100
81
The package and repository are owned by an individual rather than an organization, so the single registry maintainer reflects a genuinely thin backing structure rather than normal organizational publishing hygiene.
This is a single-release package first published about seven years ago, with no releases in the last 12 months. That is a substantial maintenance concern, though a small stable shim may need few changes.
There were zero commits and zero active maintainers in the last three months. Combined with the single historical release, this leaves no evidence of current maintenance capacity.
The repository uses Composer for its build and dependency workflow, which fits the package ecosystem. No security scanning tools are configured, a minor transparency and hygiene gap for a dependency package.
The linked repository is not archived, so it remains available for maintenance. Its last push was about seven years ago, which supports the broader concern about inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.