Usable with caveats: the package is licensed, documented, tested, and not deprecated, but it has had no release or commit activity since December 2021. The linked repository also does not mention the package in its README, so verify ownership and compatibility before adopting it.
52%
Total Score
50
75
75
The repository is owned by an individual user rather than an organization, so the single registry maintainer does not benefit from visible organizational backing.
The package has nine releases and a stable 1.2.2 version, but its latest release was in December 2021 and there were no releases in the last 12 months. The long release gap lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's multi-year release gap and indicating a meaningful abandonment risk.
The repository name matches the package, which supports the linkage, but the package name is absent from its README. That mismatch in documentation warrants verifying that the repository is the intended source.
The repository uses Composer build tooling, but it reports no security scanning tools. This is a modest transparency gap, though the absence of scanning alone does not make the package unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version >=2.3 | — | — |
creof/geo-parser Version ~2.0 | — | — |
creof/wkb-parser Version ~2.0 | — | — |
creof/wkt-parser Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.