65%
Total Score
caution
The package is only seven days old and all recent repository work comes from one contributor.
The package is only 7 days old with 4 releases, so there is too little history to establish long-term maintenance or stability. The recent release activity is encouraging but does not compensate for the short track record.
One contributor made all commits in the last 3 months, creating a concentrated maintenance risk. The organization-owned repository provides some ability to hand off maintenance, but no second active contributor is shown.
The repository recorded 2 commits in the last 3 months, which shows some recent work but remains a thin maintenance cadence for a dependency.
Composer build tooling is present, but no security scanning tools are reported. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy. For a small package this is a hygiene gap, but it does not by itself indicate abandonment or make the release unfit to use.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^5.4 || ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.