Risky to adopt: this package has had no release or repository activity for nearly nine years. It is licensed, documented, and not deprecated or archived, but its maintenance appears effectively abandoned.
45%
Total Score
50
79
75
The package has 4 releases, but its latest release was in December 2017 and there have been no releases in nearly nine years. That long gap is a substantial abandonment risk despite the earlier regular release interval.
The repository has recorded no commits and no active maintainers in the last three months, consistent with the nearly nine-year release gap. This provides no evidence of ongoing maintenance capacity.
Composer is used for builds, but the repository has no security scanning tools. This is a modest hygiene gap, though the lack of workflows also limits workflow-specific risk.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, but it is secondary to the much older maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ~3.1 | — | — |
silverstripe/framework Version ~3.1 | — | — |
sheadawson/silverstripe-shortcodable Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.