The package is small, documented, and has a focused dependency profile. Consumer safeguards and independent maintenance capacity are limited, so future support depends heavily on its current owner.
68%
Total Score
50
100
93
75
The repository is owned by the individual account basemotive rather than an organization. This is consistent with the single-contributor activity and provides no organizational handoff capacity.
One contributor made all commits in the last 3 months, giving the project a 100% top-contributor share. Because the backing owner is an individual, there is little visible maintenance redundancy.
The repository has 3 commits in the last 3 months and only one active maintainer. Recent activity exists, but the volume is modest for a package receiving frequent releases.
Composer is used as a build tool, but no security scanning tools were detected. This is a process gap for a database-oriented library, though it is not evidence of a security defect by itself.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations, particularly for a library that handles database operations.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.