Usable with caveats: it has strong documentation, tests, licensing, and active recent releases, but all recent repository work comes from one contributor and the project has no security policy or scanning. Review its maintenance plan before making it a critical dependency.
72%
Total Score
60
100
94
90
Only one registry account has publishing access. This is not proof of poor maintenance, but it leaves release administration dependent on a single person.
The registry namespace and repository owner match, but the owner is an individual user rather than an organization. This supports package identity while offering no organizational continuity beyond the current maintainer.
All 50 commits in the last three months came from one contributor, creating a significant single-person maintenance risk. The repository is user-owned rather than organization-owned, so there is no provided organizational backing to compensate for that concentration.
There are no open issues or pull requests, and no issue or pull-request activity in the last month. With active commits this is not abandonment evidence, but it provides little evidence of community support.
Composer is used as a build tool, but no security-scanning tooling was detected. The missing scanner is a genuine transparency gap for a dependency library, though it does not outweigh the evidence of active development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.0 | — | — |
doctrine/dbal Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.