The package lacks consumer documentation, automated tests, and a security policy, which makes maintenance and integration harder. Its MIT declaration and absence of install-time scripts are reassuring, but they do not compensate for the project's limited transparency.
32%
Total Score
40
50
Only one release exists, and the latest release was about 9 years ago; zero releases in the last 12 months is strong evidence that the package is abandoned.
The repository is not archived, but it has not been pushed since March 2017, corroborating the long release hiatus and indicating very limited ongoing maintenance.
The repository has 0 stars, 1 fork, and 1 watcher, providing little evidence of a broader user or contributor community to support the project.
Composer is used for builds, but no security scanning tools are configured, leaving dependency or repository security checks undocumented.
No security policy is present. For a database-related library, this is a transparency gap, although the package's age and small scope limit how much weight it carries.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mongodb/mongodb Version ^1.1 | — | — |
elasticsearch/elasticsearch Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.