The license, repository ownership, and package contents are clear, with no install-time scripts or registry deprecation. Its narrow SilverStripe 3.x requirement also limits present-day usefulness, and there is no evidence of active maintenance.
32%
Total Score
50
71
75
This package has only one release, published in May 2014, with no releases in the last 12 months. That long gap is strong evidence of abandonment risk.
There were no commits and no active maintainers in the last three months, consistent with a repository that has been inactive for about 10 years.
There has been no issue or pull-request activity in the last month. Combined with the long release and commit gaps, this provides no evidence of ongoing maintenance.
Composer is used for package management, but no security scanning tooling is present. This is a minor transparency and maintenance gap rather than a severe risk.
The repository has no security policy. For a small legacy module this is a hygiene gap, but it is secondary to the much stronger evidence of inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version 3.* | — | — |
composer/installers Version * | — | — |
silverstripe/framework Version 3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.