Tests, a clear MIT license, and organization backing support straightforward adoption. The package has no install-time scripts or deprecation notice, but it lacks a security policy and has very little repository activity or community traction.
65%
Total Score
75
100
83
75
The latest registry release was over four years ago, with no releases in the last 12 months. This is a meaningful maintenance concern, although the linked repository was pushed more recently.
There were no commits and no active maintainers in the last three months. Combined with the old registry release, this supports a concern about slowing maintenance.
The repository has zero stars, one fork, and one watcher, indicating very limited external adoption. Popularity is supporting evidence, but this modestly reduces confidence in community validation.
Composer build tooling is present, but no security scanning tooling was detected. The missing scanning is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for a library that handles database changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
doctrine/inflector Version ^2.0 | — | — |
activecollab/filesystem Version ^0.10 | — | — |
activecollab/databaseconnection Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.