Strong tests, a clear README, and release notes support adoption, while the missing security policy and unpinned workflow actions weaken transparency and build hygiene. The project is not archived, but recent repository activity and registry releases are absent.
68%
Total Score
50
100
89
75
The package has 34 releases over more than 10 years, but none in the last 12 months and the latest registry release was in November 2023. This materially raises maintenance risk despite its historically regular release interval.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with no registry releases in the last year, this indicates reduced ongoing maintenance capacity.
There are no open issues or pull requests, and no issue or pull-request activity in the last month. This is consistent with a quiet project but does not by itself prove abandonment.
Composer is used as the build tool, but no security scanning tool was detected. The missing scanner is a modest transparency and hygiene gap rather than a dependency-health verdict by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a real transparency gap for a database integration library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mongodb/mongodb Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.