The small codebase has clear licensing, a matching source repository, and a focused dependency profile. Maintenance has been quiet since May 2023, with no recent commits, releases, tests, changelog, or security policy; this raises abandonment and change-confidence concerns.
62%
Total Score
75
100
81
83
The artifact includes a README, while the absence of tests and a changelog is normal for published artifacts and is not a gap by itself. The repository also has no tests or changelog, limiting visible project safeguards.
The package has five releases over roughly ten years, with no release in the last three years. That is a meaningful sign of slow maintenance, though the package may be stable and is not deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push being in May 2023. This weakens confidence in ongoing maintenance.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap rather than a severe risk.
The linked repository has no security policy, reducing clarity about vulnerability reporting and maintenance response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.