The package has had no release or commit activity for nearly four years, and its repository lacks security scanning and a security policy. It includes tests, usage documentation, and release notes, but those strengths do not offset the maintenance risk.
15%
Total Score
0
67
50
Packagist marks the entire package as abandoned and names oskarstark/doctrine-postgres-milliseconds-platform as its replacement. This is a direct adoption risk and outweighs the package's otherwise usable metadata.
The latest release was in October 2022, with no releases in the last 12 months. That long release gap indicates the package is no longer actively maintained.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the nearly four-year release gap. The absence of recent work materially increases abandonment risk.
The repository has no security policy and no security scanning tools. For a package intended for direct application integration, this weakens transparency and vulnerability-handling readiness.
The single workflow was fully analyzed with no dangerous sinks or audit findings, but all 9 action references are unpinned. That is a supply-chain hygiene gap, though no untrusted trigger or broad write token raises it to severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.