The package has tests, a changelog, a matching repository, and a clear BSD-3-Clause license. Its maintenance activity has effectively stopped, and the repository has no security policy or scanning, making long-term dependency risk substantial.
38%
Total Score
25
81
75
The latest release was about 10 years ago, with no releases in the past 12 months. Five historical releases show some maturity, but the prolonged release silence materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers over the past 3 months, consistent with the last push being nearly 9 years ago. This strongly suggests the project is no longer maintained.
One registry maintainer is consistent with a small user-owned project, and the repository owner matches that maintainer. However, the narrow maintainer base provides little resilience alongside the long inactivity period.
Composer is used for builds, which supports reproducible project structure, but no security scanning tools are present. That leaves dependency and code risks less likely to be detected.
The repository has no security policy and no documented security contact. This is a transparency and response gap for a package that processes user-editable page content.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ~3.1 | — | — |
silverstripe/framework Version ~3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.