The module is clearly packaged, licensed, and tied to an organization-owned repository with matching documentation. Its small contributor footprint, lack of recent commits, and absent security policy reduce confidence in ongoing maintenance.
68%
Total Score
63
100
88
83
Only one registry account has publish access, which is a thin publishing base; the organization-owned repository provides some backing, but does not remove single-publisher concentration.
The package has existed since July 2019 and has four releases, but it had no releases in the last 12 months and its median release interval is about 586 days, indicating slow maintenance.
The repository recorded zero commits and zero active maintainers in the latest three months, a concrete sign that maintenance has currently gone quiet.
There are no open issues or pull requests, and no issue or pull-request activity in the latest month; this is consistent with a small stable module but offers little evidence of active support.
Composer is used for the build, but no security scanning tools were detected, leaving a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/assets Version ~1.4|~2.0|~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.