The MIT license, matching repository, and organization ownership improve transparency. There are no install-time scripts or workflow findings, but the repository lacks a security policy and provides little evidence of ongoing care.
38%
Total Score
50
64
75
This package has only one release, published more than six years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk, although the repository remains available.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing that development has stopped rather than merely slowed.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these values provide no meaningful adoption signal to offset inactivity.
The repository is not archived, which preserves the possibility of future maintenance, but its last push was more than five years ago and does not offset the inactive release and commit history.
No security policy was found in the repository. For a code-generation and framework package, that is a transparency gap, though it is less significant than the lack of maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^2.10 | — | — |
devel/module-installer-composer-plugin Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.