The package has a clear README, changelog, focused dependency set, and a repository that matches its name. However, it has had no commits or active maintainers in the last three months, and the license signals do not fully agree.
60%
Total Score
75
100
78
88
The release includes a LICENSE.md file and is therefore licensed, but the manifest declares MIT while the detected license also includes BSD-3-Clause. That mismatch reduces transparency slightly.
The package is only 140 days old and all 10 releases occurred on the same day, so there is not yet evidence of sustained release maintenance.
The repository had zero commits and zero active maintainers in the last three months, indicating that maintenance has currently stalled after the release.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no external indication of adoption or review.
Composer is used for the build, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.