The package includes tests, a readable README, and no install-time scripts. However, it has had no registry release for over six years and no recent repository commits, while its detected GPL-2.0 license conflicts with the declared LGPL-3.0-or-later.
42%
Total Score
0
100
60
83
The latest release was published on June 22, 2019, and there were no releases in the following 12 months of the scan window. This is a substantial abandonment concern for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the long release gap rather than showing active maintenance.
A license file is present, but it was detected as GPL-2.0 while the manifest declares LGPL-3.0-or-later. That mismatch creates avoidable legal uncertainty for adopters.
Composer is used as a build tool, but no security scanning tools were detected. This is a modest hygiene gap and does not by itself establish that the release is unsafe.
The repository has no security policy. This weakens transparency for a package focused on constructing SQL queries, although the inactivity and license mismatch are more significant concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/framework-bundle Version >=3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.