Package Health

micschk/silverstripe-cmstweaks

Documentation, tests, and release notes make the code easier to adopt. Recent repository commits are absent, workflow references are all unpinned, and bundled licenses extend beyond the declared MIT license.

Latest 4.1.0PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Registry deprecationdanger

The registry marks the entire package as abandoned and names restruct/silverstripe-admintweaks as its replacement. This is a direct adoption concern even though the assessed release is current.

Licensecaution

The package declares MIT and includes license files, but the artifact also contains CC-BY-4.0 and OFL-1.1 notices for bundled assets. Those additional licenses deserve review because they are not covered by the single declared license.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months. The current release and recent push provide some context, but this still indicates weak recent development activity.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention micschk/silverstripe-cmstweaks. Although this can happen with renamed or republished packages, the mismatch reduces source-to-artifact transparency.

Security policycaution

The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is less serious than the package-level abandonment status.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Restruct

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.0
—
—
silverstripe/framework
Version ^6
—
—
silverstripe/vendor-plugin
Version ^3
—
—

Weekly Downloads

Info

Last Published
2 days ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform