The package is compact, clearly documented, licensed, and backed by a matching organization repository. Maintenance evidence is thin, with no commits in the last three months, no tests, and no security scanning; its very small user base also limits independent validation.
64%
Total Score
75
100
83
75
The package has existed for about 5 years, but only 3 releases with a median interval of about 2 years 4 months indicate a slow release cadence. A release in the last 12 months partly offsets the concern.
There were no commits and no active maintainers in the last three months. The recent release provides some counterevidence, but the current absence of development activity is a maintenance concern.
The repository has no stars or forks and only 3 watchers, offering little independent evidence of adoption or community support. Popularity is supporting evidence, so this is a modest concern rather than a decisive risk.
Composer is used for builds, but no security scanning tools are configured. This weakens supply-chain hygiene evidence without making the release unfit by itself.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version * | — | — |
silverstripe/framework Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.