It has a clear README, an MIT license, and no install scripts, but the tiny project shows little recent activity or security process. Its narrow scope and simple dependency set reduce complexity, not abandonment risk.
40%
Total Score
50
100
67
50
The package has only one release, published nearly 12 years ago, with no releases in the last 12 months. This is strong evidence of an unmaintained release line.
There are no recent issues or merged pull requests, while one pull request remains open. This does not prove abandonment alone, but it is consistent with the repository's long inactivity.
The repository has one star and one fork, indicating a very small adoption and contributor footprint. Popularity is only supporting evidence, but it provides little evidence of outside maintenance capacity.
The repository is not archived, which preserves a path for maintenance, but it was last pushed in 2016. That old activity materially increases abandonment risk.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a secondary transparency concern for a package with otherwise limited recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version >=3.1.0 | — | — |
silverstripe/framework Version >=3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.