The MIT license, clear README, and matching source repository make the package transparent and straightforward to inspect. No commits were recorded in the last 3 months, and the repository has no security policy, so ongoing support and response expectations are limited.
58%
Total Score
50
78
75
The package has had only one release, published about 10 years ago, with no releases in the last 12 months. This is a significant maintenance and compatibility concern despite the repository being updated more recently.
No commits and no active maintainers were recorded in the last 3 months. Combined with a single registry release, this leaves current maintenance capacity uncertain.
The repository has only 4 stars and 3 forks, so there is little evidence of broad community use or backup. Popularity is supporting evidence rather than a verdict, but this provides no meaningful resilience signal.
Composer is used for the build, giving the project basic ecosystem tooling, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap.
The repository has no security policy. For a small package this is not severe on its own, but it gives users no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version >=3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.