The source is clearly linked to the package and backed by an organization, with a matching README and release notes. Its BSD-3-Clause licensing and lack of install scripts are reassuring, but the old registry release history and recent lack of commits make maintenance uncertain.
58%
Total Score
75
71
83
The artifact lacks a README, tests, and changelog, but the repository has a README and this exact version has GitHub release notes documenting its changes; missing tests remain a modest maturity gap.
The latest registry release was over three years ago, with no releases in the last 12 months; the earlier 27-day median interval shows that maintenance has stopped rather than always being slow.
There were no commits or active maintainers in the last three months, reinforcing the concern raised by the absence of recent registry releases.
Composer is used for builds, but no security scanning tooling was detected; this is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
heyday/silverstripe-elastica Version ^2.2|^4.1 | — | — |
nglasl/silverstripe-extensible-search Version ^4.1 | — | — |
symbiote/silverstripe-multivaluefield Version ^5.1.0 | — | — |
nyeholt/silverstripe-extensible-elastic Version ^2.10.0|^3.0 | — | — |
nswdpc/silverstripe-elemental-extensible-search Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.