Low adoption and no security policy add to the maintenance concern, although the repository is clearly tied to the package and backed by an organization. Its license, documentation, and lack of install-time scripts reduce transparency and operational risk, but do not offset the prolonged inactivity.
45%
Total Score
50
70
75
The latest release was published in July 2016, with no releases in the last 12 months. Nearly 10 years without a release is strong evidence of abandonment for a framework integration package.
The repository recorded zero commits and zero active maintainers in the last 3 months, while its last push was in August 2020. This indicates prolonged inactivity rather than an actively maintained project.
The repository has only 1 star, 2 forks, and 1 watcher. Popularity is not decisive, but these very low figures provide little supporting evidence of ongoing community use or review.
The linked repository has no security policy. This is a transparency and response-process gap, though the package's long inactivity is the more significant concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/composer Version ^1.1 | — | — |
silverstripe/framework Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.