The package is clearly licensed, matches its source repository, and has no install-time scripts. Its stable release and release notes help, but only two releases and roughly 11 months without commits indicate limited maintenance capacity.
67%
Total Score
83
100
88
75
There have been only two releases over about 21 months, with one release in the last year. That is a sparse cadence for a dependency, though the recent 1.1.0 release provides some evidence of ongoing support.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the release history, this points to limited current maintenance capacity.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy. For a small form-field package this is a hygiene gap, but it does not outweigh the available source and licensing evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^5.0 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.