The package is only 90 days old, but it has shipped eight stable releases and remains actively pushed. Organization backing and readme/tests help offset the single-contributor concentration; pin the workflow's three action references if reproducibility matters.
78%
Total Score
83
50
93
50
The package declares 13 runtime dependencies, reflecting a broad integration surface for its ORM and framework role. That increases maintenance exposure somewhat, but the dependency set is coherent with the documented package purpose.
All 10 recent commits came from one contributor, creating concentration risk. Organization ownership provides some handoff capacity, so this is a caution rather than a severe abandonment signal.
The project uses Composer build tooling, but no security scanning tool was detected. The missing scanner reduces transparency around automated security checks without indicating a direct release defect.
The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, although it is not evidence that the release is unsafe.
The single workflow was fully analyzed, uses read-only permissions, and has no detected dangerous sinks or audit findings. However, all 3 action references are unpinned, leaving the build exposed to dependency-reference drift.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cycle/orm Version ^2.12 | — | — |
componenta/di Version ^5.0.3 | — | — |
nesbot/carbon Version ^3.0 | — | — |
psr/container Version ^2.0 | — | — |
cycle/database Version ^2.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.