It has a clear BSD-3-Clause license, a README, changelog, and repository tests, with no registry deprecation. However, its README says it is out of date, and both registry and repository activity stopped in May 2018; the absent security policy adds little confidence.
35%
Total Score
0
79
50
The latest release was in May 2018, with no releases in the last 12 months. This long period without published updates is strong evidence of abandonment risk for a dependency.
There were zero commits and zero active maintainers in the last three months, consistent with the last repository push having occurred in May 2018. This is a substantial maintenance and abandonment concern.
The artifact includes a README and changelog, while the repository contains tests and a changelog. The README's explicit note that the module is out of date materially reduces the value of that documentation.
The repository has no security policy. This is a transparency gap, though it is less significant than the long-standing lack of maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ~2.4 | — | — |
sunnysideup/ecommerce Version ~2.4 | — | — |
silverstripe/framework Version ~2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.