Usable with caveats: the package is clearly tied to a real repository, licensed, documented, and includes tests and release notes in its source. It is brand new with no demonstrated maintenance history, has one registry maintainer, and lacks a security policy and explicit workflow permissions.
62%
Total Score
50
100
88
80
Only one account has registry publish access. That is a thin publishing base for an independently owned package and provides limited redundancy if the maintainer becomes unavailable.
The registry namespace and repository are owned by the same individual account. This confirms ownership alignment but does not provide organizational backing or maintainer redundancy.
This is the first release and the package is only 0 days old, so there is no established release cadence or long-term maintenance record yet.
The repository has zero commits and zero active maintainers in the preceding 3 months. Because the package is newly released, this is more a lack of proven maintenance capacity than evidence of abandonment, but it remains a concern.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency gap for supply-chain maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/admin Version ^2.0 | — | — |
silverstripe/assets Version ^2.0 | — | — |
silverstripe/framework Version ^5.0 | — | — |
silverstripe/versioned Version ^2.0 | — | — |
unclecheese/display-logic Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.