The repository includes tests, release notes, a clear MIT license, and no install-time scripts. However, the package has had no registry release for over two years and no recent commit activity, so pinning this release carries meaningful maintenance risk.
42%
Total Score
75
79
67
Packagist marks the entire package as abandoned, which is a serious adoption concern even though the listed replacement uses the same project name under the source organization.
The package has 32 releases since September 2015, but its latest release was over two years ago and it had no releases in the last 12 months. That supports a material maintenance concern.
The repository recorded zero commits and zero active maintainers in the last three months. The repository was pushed more recently, but current development activity is still absent.
The repository has no published security policy. This reduces vulnerability-reporting transparency, although it does not by itself show abandonment.
All three workflows were analyzed without high- or medium-confidence findings, and two use read-only permissions. However, all three analyzed action references are unpinned, leaving a modest workflow hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/composer Version ^2 | — | — |
silverstripe/framework Version ^5 | — | — |
bringyourownideas/silverstripe-maintenance Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.