The repository includes tests, a README, and release notes, while its license and dependency set are straightforward. Workflow pinning and missing security scanning weaken transparency, and the small project has little evidence of sustained activity.
61%
Total Score
50
100
81
83
The registry lists one maintainer. That is a thin publishing base and leaves limited visible redundancy if the maintainer becomes unavailable.
This is the only release, published about 183 days ago, so there is limited evidence of a sustained release track. The linked repository and release notes provide some transparency, but do not offset the lack of release history.
The repository recorded 0 commits and 0 active maintainers in the last three months. For a package only about six months old, this is a meaningful maintenance concern, though not proof of abandonment by itself.
Composer build tooling is present, but no security scanning tools are configured. The missing scanner is a transparency and maintenance-hygiene gap, not evidence of malicious behavior.
The repository has no security policy. That leaves vulnerability reporting and disclosure expectations undocumented for a toolkit that handles database operations.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.