Tests, a license file, and no install-time scripts provide useful baseline safeguards. The beta status, almost six years without a release, and no recent commits make this a poor choice for a new dependency.
38%
Total Score
50
58
100
Only two releases exist, with none in the last 12 months; the latest release was in December 2020, almost six years before collection. This is strong evidence of abandonment risk.
The repository had zero commits and zero active maintainers in the last three months. Combined with the stale release history, this indicates no current maintenance activity.
A LICENSE file is present and identifies MIT, but the manifest declares the package proprietary. This mismatch creates avoidable licensing uncertainty despite the available license text.
Composer is used for the build, but no security-scanning tooling was detected. The missing scanner is a hygiene weakness, not by itself evidence that the package is unsafe to depend on.
The assessed version is a prerelease beta, and all recent releases are prereleases. That leaves the package without a demonstrated stable release line.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/mongodb-odm Version ^2.0.5 | — | — |
3slab/vdm-library-bundle Version ^2.0@beta | — | — |
doctrine/mongodb-odm-bundle Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.