A clear README, matching repository, and BSD-3-Clause licensing make the package easy to verify and adopt. Its small footprint and organization ownership partly offset the quiet recent repository, but there is no security policy or automated scanning.
64%
Total Score
67
100
88
83
The repository recorded zero commits and zero active maintainers during the last three months. With no other activity signal showing continued development, this raises maintenance and abandonment risk.
There have been seven releases since March 2024, including two in the last 12 months, with the latest released on April 13, 2026. This shows some ongoing publishing but a relatively light recent cadence.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tool is configured. The missing scanning is a modest transparency and maintenance gap for a dependency.
The repository has no security policy. For a small CMS extension this is not severe by itself, but it leaves vulnerability reporting expectations and response ownership unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.