Healthy and suitable to depend on. It has a long release history, a recent stable release, active commits, tests, clear licensing, and a matching source repository; the main caveat is that all recent commits come from one contributor and the repository lacks a security policy.
86%
Total Score
67
100
94
80
The registry namespace and repository are owned by the same individual account, so there is no organization backing to offset the concentrated maintainer base. The package's long history and current activity still provide meaningful support.
One contributor made all 18 commits during the last three months, creating a genuine continuity risk. The active release cadence and substantial project maturity partly compensate, but they do not remove the single-maintainer dependence.
Composer is used as a build tool, but no security scanning tools were detected. This is a modest transparency and assurance gap rather than evidence that the package is unsafe.
The repository has no security policy, so vulnerability reporting and disclosure expectations are less explicit. The mature repository and active maintenance provide some compensation, but this remains a documentation gap.
The one workflow has no top-level token permissions declaration. Although it requests no declared top-level write access, explicitly limiting permissions would provide stronger CI security hygiene.
| Title | Versions | Severity |
|---|---|---|
CVE-2019-10762 catfan/medoo is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 1.7.5. | 0.0.0 - 1.7.5 | Critical |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.