The MIT license, focused dependencies, and matching organization repository improve transparency. Missing security policy and security-scanning tools leave project safeguards unclear.
54%
Total Score
100
100
64
50
The package has had no release in about 3 years 8 months, despite only four releases overall. The early release activity was brief, so current maintenance capacity is uncertain.
The project uses Make and Composer, showing some build structure, but no security-scanning tools were detected. That is a modest transparency and maintenance gap.
The repository is not archived, but its last push was about 3 years 8 months ago. That supports the maintenance concern from the release history without indicating formal abandonment.
The linked repository has no security policy. For a module involved in cache-purge behavior, the lack of a stated vulnerability-reporting process reduces transparency.
Version 1.0.0-rc4 is still a prerelease, and all recent releases are prereleases. That leaves the public API and production support expectations less certain.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^4.6.0@stable | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.