The organization-backed repository has clear documentation, tests, release notes, and licensing. Maintenance has slowed substantially, and all three analyzed workflow actions are unpinned, so pinning this version warrants ongoing monitoring.
62%
Total Score
67
100
88
67
The package has 34 releases over roughly 12 years, but no releases in the last 12 months and its latest registry release was about two years ago, indicating slowed maintenance.
There were no commits and no active maintainers in the last three months, a meaningful sign of currently reduced maintenance capacity.
No issues or pull requests were opened, closed, or merged in the last month, consistent with the observed slowdown in project activity.
The repository uses Composer for builds, but no security scanning tooling was detected, leaving a modest transparency and hygiene gap.
The repository has no published security policy, making vulnerability reporting less clear for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^5 | — | — |
silverstripe/framework Version ^5 | — | — |
silverstripe/versioned Version ^2 | — | — |
silverstripe/vendor-plugin Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.