The source repository is active and well documented, with tests, release notes, and safe CI practices. Maintenance is concentrated in one contributor, and this release is still a release candidate.
45%
Total Score
75
75
67
Packagist marks the entire package as abandoned, which is a serious adoption concern; the listed replacement points to the same maintained project, partly reducing the risk but not removing the registry warning.
The package has existed since 2018 with 23 releases, but only one release in the last 12 months indicates a slower release cadence.
All five commits in the last three months came from one contributor, leaving maintenance dependent on a single active individual despite organization backing.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The workflow lacks top-level token permissions, so its effective permissions are not explicitly minimized at the workflow level.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^6.0 | — | — |
silverstripe/admin Version ^3.0 | — | — |
silverstripe/framework Version ^6.0 | — | — |
unclecheese/display-logic Version ^4.0 | — | — |
symbiote/silverstripe-gridfieldextensions Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.