Its focused artifact is easy to inspect, clearly licensed, and free of install-time scripts. The small project has no commits in the last three months and no security policy, so long-term maintenance coverage is limited.
70%
Total Score
75
100
88
83
The package has existed since June 2020 and released once in the last 12 months, including the assessed release in March 2026. Its long median interval of about 660 days indicates a deliberately slow cadence, but not abandonment by itself.
The repository recorded zero commits and zero active maintainers during the last three months. The March 2026 release is recent, but the lack of ongoing commit activity limits evidence of active maintenance.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are configured. The missing scanning is a modest transparency and hygiene concern rather than a release blocker.
The repository has no security policy. For a small focused module this is not severe, but it leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^6 | — | — |
silverstripe/framework Version ^6 | — | — |
silverstripe/lumberjack Version ^4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.