Usable with caveats: this is a clearly identified, licensed package with a readable README, matching repository, and no deprecation or risky install scripts. It is brand new with no demonstrated maintenance history, no commits beyond its initial release, and no security policy.
68%
Total Score
75
100
83
75
The package was first and last released today, with only one release and no established release history. This is an important maturity gap, although the release is too new for inactivity alone to indicate abandonment.
There were no commits or active maintainers in the last three months beyond the initial project publication. Because the package is newly released, this primarily means maintenance capacity is unproven rather than demonstrating long-term abandonment.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but popularity is not required for a small, focused package and the project is newly released.
Composer is used as a build tool, but no security scanning tooling is present. The missing scanning is a transparency gap, though the repository has no workflows that would otherwise introduce workflow-specific risk.
The repository has no security policy. For a package that handles CSRF-token endpoints, the absence of a documented vulnerability-reporting process is a meaningful transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^5 || ^6 | — | — |
silverstripe/framework Version ^5 || ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.