The project has no security policy and no automated security scanning. It is licensed, linked to the matching repository, and has no install-time scripts.
42%
Total Score
0
60
75
The latest registry release was published in November 2019, with no releases in the last 12 months. This long period without updates is a strong abandonment concern for a framework integration.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the stale release history and indicating no visible ongoing maintenance.
Composer is used for builds, but no security scanning tools were detected. That leaves dependency and source security checks less transparent, especially for an unmaintained package.
The repository has no security policy. This weakens vulnerability-reporting and response transparency, with no provided evidence of another process compensating for the gap.
The assessed version is 3.0.0, while the recorded latest version is 2.4.0. The release appears stable rather than prerelease, but the version discrepancy reduces confidence in its current maintenance state.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ~4.0 | — | — |
bummzack/sortablefile Version * | — | — |
silverstripe/framework Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.