The package has a clear README, changelog, BSD-3-Clause license, and only two runtime dependencies. Its repository is identifiable and not archived, but it lacks a security policy and recorded recent commits.
61%
Total Score
50
100
83
83
The package and repository share the sunnysideup owner, but the backing is an individual account rather than an organization, so institutional maintenance capacity is limited.
The latest release is over three years old, with no releases in the last 12 months; the four releases were clustered within minutes, indicating a thin release history.
There were no commits or active maintainers in the last three months, which weakens evidence of ongoing maintenance even though the repository is not archived.
The repository has zero stars, one fork, and one watcher, showing limited adoption; this is supporting evidence only and does not establish abandonment by itself.
Composer is used for builds, but no security-scanning tool is configured, leaving a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^4.0 || ^5.0 | — | — |
jonom/silverstripe-image-coord Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.