The small contributor footprint and lack of security tooling reduce confidence in ongoing support. Clear ownership, licensing, documentation, and a recent release provide useful reassurance for this focused package.
65%
Total Score
75
81
75
The package has existed since 2013, but it has only seven releases and none in the last 12 months; the latest release was about 15 months ago. This indicates slow maintenance rather than abandonment on its own.
The repository recorded no commits and no active maintainers in the last three months. The repository was pushed alongside the latest release, but current activity is still limited.
The repository has zero stars, one fork, and three watchers, so there is little public adoption evidence. Popularity is supporting evidence only, and the package's focused scope partly explains the small audience.
Composer is used for the build, but no security-scanning tools are present. The build setup supports reproducibility, while the missing scanning reduces maintenance hygiene.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^4|^5|^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.