The package has a long release history, stable versioning, tests, documentation, and a source repository that matches the package. Composer tooling and Psalm provide useful safeguards, while the recent lack of commits warrants monitoring.
74%
Total Score
67
100
100
50
The package declares a post-update Composer lifecycle script. This is a supply-chain-sensitive behavior that deserves review, although the signal alone does not show that the script is unsafe.
Only one registry account, daycry, has publishing access. That creates a thin release bus factor, although the release history shows that this maintainer has continued publishing regularly.
There were no commits and no active maintainers in the last 3 months. This is a recent maintenance gap, partly offset by seven registry releases in the last 12 months and a push accompanying the assessed release.
No repository security policy was found. This is a transparency and vulnerability-reporting gap, but it is not severe enough to make the release unfit on its own.
All 6 workflows were analyzed with no reported audit findings or untrusted-trigger sinks, but all 21 action references are unpinned and one workflow has top-level write permissions. The broad permissions are limited in concern because no untrusted workflow path was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3 | — | — |
doctrine/dbal Version ^4 | — | — |
symfony/cache Version ^7 | — | — |
beberlei/doctrineextensions Version ^1.0 | — | — |
scienta/doctrine-json-functions Version ^6.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.