Risky to adopt without taking ownership: the last release and repository push were over eight years ago, with no commits in the past three months. It has tests, a README, a matching organization-backed repository, and no deprecation notice, but maintenance appears effectively stopped.
42%
Total Score
50
69
83
The package has had no release in over eight years and has only four releases overall, despite a relatively short median interval during its initial release period. This is a substantial maintenance and compatibility risk.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the last push occurring over eight years ago. This strongly increases abandonment risk.
Composer is used for the project build, but no security scanning tools are present. The missing scanning is a modest transparency concern, especially for an otherwise dormant project.
The repository is not archived, which is a positive ownership signal, but its last push was over eight years ago and the lack of recent commits shows that it is effectively dormant.
The repository has no security policy, leaving vulnerability reporting and response expectations unspecified. This is a hygiene gap, though not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ~4.0 | — | — |
symbiote/silverstripe-multisites Version ~5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.