The package is well documented, licensed, and actively released, with repository tests. No security policy or scanning is visible, so long-term support and security transparency remain limited.
68%
Total Score
50
100
93
75
The repository owner is a user account rather than an organization, and the provided ownership data does not show organizational backing. This provides no compensating support for the concentrated contributor base.
One contributor made all 16 commits in the last three months, giving the project a bus factor of one. No second active contributor is shown to provide handoff capacity.
There were 16 commits in the last three months, showing ongoing work. However, all activity is concentrated in one active maintainer, which reduces resilience if that maintainer stops contributing.
Composer build tooling is present, but no security-scanning tools are configured. The build setup is appropriate, while security visibility is limited.
The repository has no security policy. For a database abstraction library, that leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
callismart/dto Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.