The package is small and focused, with a single runtime dependency and a matching organization-owned repository. Its license and publication structure are clear, but limited recent activity and missing security guidance leave some maintenance risk.
68%
Total Score
67
100
88
50
The latest registry release was about one year ago, with no releases in the last 12 months. A recent repository push provides some compensating evidence that the project is not abandoned, but the release cadence remains sparse.
All recent commits came from one contributor. Organization ownership offers some handoff capacity, but no second active contributor is shown to reduce the immediate concentration risk.
Only one commit was recorded in the last three months from one active maintainer. This shows some recent maintenance but is a sparse pace for ongoing support.
Composer is used for the build, which fits the package ecosystem. No security scanning tooling is present, leaving a modest assurance gap.
The repository has no security policy. For a small UI extension this is not severe, but it reduces clarity about vulnerability reporting and maintenance response.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.