A single publisher and no security policy limit maintenance depth and transparency. The package has a clear README, matching source repository, release notes, and no install-time scripts.
58%
Total Score
50
100
71
83
Only one registry account has publish access. That is a thin publishing base and leaves limited visible redundancy if the maintainer becomes inactive.
The repository is owned by the same individual named in the registry namespace, so the source and publishing ownership are consistent. Individual ownership still offers less organizational backing than a maintained team project.
The package has had 3 releases, but none in the last 12 months and the latest was published about 2 years and 9 months ago. This is a meaningful maintenance concern for an experimental module.
The repository uses Composer for builds, but no security-scanning tooling was detected. The missing scanning is a transparency and maintenance gap, not proof of a security problem.
The linked repository is not archived, although its last recorded push was about 2 years and 8 months ago. The active archive status is reassuring, but the old push date is consistent with the release-history concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/graphql Version ^5 | — | — |
silverstripe/sharedraftcontent Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.