Unfit for new projects: Packagist marks this package deprecated, and its own documentation recommends PHP attributes instead. It remains well-backed and tested, but the last release was about two years ago and recent repository activity is absent.
20%
Total Score
75
100
83
67
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption and maintenance-risk signal for a new dependency.
The package has a long release history with 43 releases, but its latest release was about two years ago and there were no releases in the last 12 months. That supports the documented transition to a feature-complete, bugfix-only project but reduces confidence in ongoing maintenance.
There were no commits and no active maintainers during the last three months. This is consistent with a feature-complete project but still leaves little evidence of current maintenance capacity.
The repository has no security policy. This is a transparency gap, although the project's static-analysis tooling and feature-complete scope provide some compensating evidence.
None of the six workflows declares top-level token permissions, leaving workflow access less explicit than recommended. No workflow declares top-level write access, limiting the severity of this concern.
| Title | Versions | Severity |
|---|---|---|
CVE-2015-5723 doctrine/annotations is vulnerable to Security Vulnerability in versions 0.0.0 - 1.2.7. | 0.0.0 - 1.2.7 | High |
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1 || ^2 || ^3 | — | — |
doctrine/lexer Version ^2 || ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.