Usable with caveats: it is a small, stable package with a clear README, minimal runtime dependencies, and an active, unarchived repository. However, releases are infrequent, no commits were recorded in the last three months, and the project provides no license file or security policy.
60%
Total Score
50
100
81
75
No declared license or license file was found in either the package or repository, creating a genuine legal transparency concern for downstream users.
The package has existed for over 10 years and has a recent release, but only five releases overall and none in the last 12 months indicate a slow maintenance cadence.
No commits or active maintainers were recorded in the last three months, which weakens confidence in ongoing maintenance even though the repository is not archived.
The repository uses Composer, but no security scanning tools were detected; this is a maintenance and transparency gap rather than evidence of an unsafe package.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^4.0 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.