Usable with caveats: this is a small, clearly identified package with a stable 5.0 release, a matching repository, and a recent release. Maintenance is sparse, with only two releases overall and no commits in the last three months, so verify compatibility before adopting it.
68%
Total Score
67
100
88
75
One registry account publishes the package, creating a limited publishing base. This is a user-owned project with matching repository ownership, so the small maintainer list is a modest concern rather than a severe transparency problem.
There have been only two releases since December 2020, with no releases in the last 12 months and a median interval of about 4.5 years. That sparse history limits evidence of sustained maintenance, although the latest release was published in May 2025.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the sparse release history, this is evidence of limited ongoing maintenance, though the package is small and its latest release is not obsolete by itself.
The repository uses Composer, which fits the package ecosystem, but it has no security scanning tooling. For a small CSS-focused package this is a hygiene gap rather than a severe dependency risk.
The repository has no published security policy, reducing transparency about how vulnerabilities would be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/admin Version ~1 || ^2 | — | — |
silverstripe/framework Version ^4 || ^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.