The BSD-3-Clause license, focused file tree, and release notes make the package transparent enough to inspect. Its organization-owned repository is not archived, but maintenance appears dormant, so pinning this version is prudent.
58%
Total Score
67
100
88
88
Only one registry account has publish access, which is a modest resilience concern. The organization-owned repository provides some backing, so this is not by itself evidence of abandonment.
The package has had no registry release for about nine years, despite six historical releases. This is a meaningful maintenance concern, though the linked repository was pushed more recently than the last release.
There were no commits and no active maintainers in the last three months. Combined with the old latest registry release, this points to weak current maintenance.
Composer is used as the build tool, but no security-scanning tool was detected. The missing scanner is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy. For a small module this is a transparency and response-process gap, but it is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^4@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.