The package has thorough usage documentation and a source repository that matches its name. Its one-person ownership and absent tests and security policy leave little evidence of ongoing care.
35%
Total Score
50
63
50
Only one registry maintainer is listed, leaving limited visible publishing capacity and increasing dependence on a single person. The matching source repository provides some corroboration but does not offset the narrow maintainer base.
The last release was in August 2018, with no releases in the past 12 months despite the package being about eight years old. This is strong evidence of abandonment risk.
The repository recorded no commits and no active maintainers during the last three months, consistent with the unchanged release history and increasing abandonment risk.
Composer build tooling is present, but no security scanning tools were detected. For a small, long-inactive package this reduces maintenance transparency, though it is not severe on its own.
The linked repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap for a database-access library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.