Clear licensing and a matching organization-owned repository provide useful transparency. The package has no published security policy or repository security scanning, so maintenance safeguards are limited.
62%
Total Score
75
88
75
The package has 13 releases since May 2016, but none in the last three years, indicating a long period without registry updates despite its stable release history.
The repository recorded no commits and no active maintainers in the last three months, which is a meaningful sign of currently limited maintenance activity.
Composer is used for builds, but no security scanning tools are configured. That leaves dependency and source checks less evident than they could be.
The repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, though it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~7.2 | — | — |
silverstripe/admin Version ~1.0|~2.0 | — | — |
silverstripe/framework Version ~4.0|~5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.