It has tests, a matching repository, MIT licensing, and recent commits supported by Dependabot. The single-contributor project has no security policy, and all eight workflow actions are unpinned.
15%
Total Score
50
71
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe dependency-maintenance warning for the assessed release.
The linked GitHub repository is archived, which strongly indicates that normal future maintenance is not expected even though it was pushed recently.
All 7 commits in the last 3 months came from one contributor, leaving maintenance dependent on a single person. Organization backing provides some handoff capacity, but no second active contributor is shown.
The repository has no security policy, reducing transparency about how dependency vulnerabilities should be reported and handled.
Both workflows were fully analyzed with no dangerous triggers or audit findings, but all 8 referenced actions are unpinned, leaving workflow dependencies exposed to mutable upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.1 | — | — |
beberlei/assert Version ^3.0 | — | — |
broadway/broadway-saga Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.