The project has been published for over 11 years and the current release is stable, licensed, documented, and not deprecated. Recent repository activity is quiet, with no commits in the last three months, 12 open issues, and no security policy or scanning.
71%
Total Score
50
100
94
83
The package and repository are consistently owned by the same individual account rather than an organization. This is not inherently unhealthy, but it leaves less visible organizational backing than an organization-owned project.
The repository recorded zero commits and zero active maintainers in the last three months. The recent release history partly offsets this, but the current maintenance pause is a genuine concern.
There are 12 open issues and no issues or pull requests were opened, closed, or merged in the last month. This suggests limited recent responsiveness.
Composer is used as the build tool, but no security scanning tools are present. For a package handling CAPTCHA integration, the missing automated security coverage is a modest transparency concern.
The repository has no security policy. That leaves vulnerability reporting and maintainer response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^6 | — | — |
silverstripe/spamprotection Version ^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.