Package Health

nyeholt/silverstripe-simplewiki

The package has tests, a changelog, a matching repository, and a clear BSD-3-Clause license. Its maintenance activity has effectively stopped, and the repository has no security policy or scanning, making long-term dependency risk substantial.

Latest 1.3.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was about 10 years ago, with no releases in the past 12 months. Five historical releases show some maturity, but the prolonged release silence materially raises abandonment risk.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers over the past 3 months, consistent with the last push being nearly 9 years ago. This strongly suggests the project is no longer maintained.

Maintainerscaution

One registry maintainer is consistent with a small user-owned project, and the repository owner matches that maintainer. However, the narrow maintainer base provides little resilience alongside the long inactivity period.

Repo toolingcaution

Composer is used for builds, which supports reproducible project structure, but no security scanning tools are present. That leaves dependency and code risks less likely to be detected.

Security policycaution

The repository has no security policy and no documented security contact. This is a transparency and response gap for a package that processes user-editable page content.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marcus Nyeholt

Direct Dependencies

DependencyLast ReleaseScore
silverstripe/cms
Version ~3.1
silverstripe/framework
Version ~3.1

Weekly Downloads

Info

Last Published
10 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform