There is no security scanning, and the repository has no automated tests or changelog. The LGPL license, README, and lack of install scripts provide basic transparency but do not restore maintenance capacity.
30%
Total Score
25
75
75
The package has only one release, published in May 2013, with no releases in the last 12 months. This is strong evidence that the release is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months, with its last push in May 2015. That long gap materially raises abandonment risk.
There were no new or closed issues or pull requests in the last month, while three issues remain open. This supports the evidence of an inactive project.
The repository has only 3 stars, 0 forks, and 2 watchers. Low adoption is supporting evidence of limited maturity, though it is not decisive by itself.
Composer is used for builds, which is a positive reproducibility signal, but no security scanning tools are configured. The missing security coverage is a maintenance and transparency gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version 2.2.x | — | — |
symfony/console Version 2.2.x | — | — |
propel/propel_runtime Version 1.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.