Clear licensing, repository tests, release notes, and organization backing support adoption. The workflows use unpinned actions; pin them before relying on automated releases.
64%
Total Score
67
100
88
75
The package has 42 releases over roughly 12 years, but no registry release in the last 12 months despite a previously regular cadence. This is a meaningful maintenance concern, though the latest release is documented and the repository remains active enough to be credible.
There were no commits and no active maintainers in the three months measured. This supports the release-history concern and lowers confidence in near-term maintenance.
There were no new or closed issues or pull requests in the last month, although only two issues and one pull request are open. This is a modest sign of limited current activity rather than a severe concern.
The project uses Composer build tooling, but no security scanning tools were detected. That is a transparency and hygiene gap, partially offset by the repository's tests and CI workflows.
The repository has no security policy. This weakens vulnerability-reporting transparency, but it does not by itself show that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^6 | — | — |
dragonmantank/cron-expression Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.