Its README, license, stable major version, and recent repository push support straightforward adoption. The small maintainer base and lack of security tooling leave less independent oversight.
67%
Total Score
83
100
83
83
The package has five releases over about two years, but none in the last 12 months despite the latest release being in September 2025. This indicates a slower maintenance cadence, though the package is not obviously abandoned.
The repository recorded no commits and no active maintainers in the last three months. A repository push in May 2026 provides some recent activity, but the current short-term inactivity still lowers confidence in ongoing maintenance.
Composer is used for the build, but no security scanning tool was detected. The missing scanning is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy. This leaves vulnerability reporting and disclosure expectations undocumented, a real but limited transparency gap for a small package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.