The README is substantial and the dependency set is small. The license file says MIT while the manifest declares BSD-3-Clause, and no security policy or scanning is present.
55%
Total Score
50
75
50
A LICENSE file is present, but it is recognised as MIT while the manifest declares BSD-3-Clause. The mismatch reduces transparency about the release's applicable terms.
The latest registry release was over two years ago, with no releases in the last 12 months. This is a meaningful maintenance concern, although the repository is not archived and was pushed more recently.
The repository recorded 0 commits and 0 active maintainers in the last three months. That weakens evidence of ongoing maintenance, despite a more recent recorded push outside this window.
Composer build tooling is present, but no security scanning tools were detected. That leaves less evidence of routine vulnerability hygiene.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^4.0 || ^5.0 | — | — |
dnadesign/silverstripe-elemental Version * | — | — |
jellygnite/silverstripe-sliderfield Version dev-feature/CMS-5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.