Risky to adopt: the package is explicitly deprecated and has had no registry release for over four years. The repository remains maintained enough to be unarchived and the release is licensed and documented, but the project directs users to newer PSR-6 or PSR-16 alternatives.
35%
Total Score
75
100
64
67
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because the README also says the Doctrine Project will no longer provide bug fixes.
The package has 43 releases over a long history, but its latest release was in May 2022 and there were no releases in the last 12 months. That extended release gap materially raises abandonment and compatibility risk.
There were no commits and no active maintainers in the three months measured. Although the repository was pushed in October 2025, the recent activity window still indicates limited ongoing development.
The repository uses Composer and Phing for builds, but no security scanning tools were detected. This is a transparency and maintenance gap, though it is less important than the explicit package deprecation.
No security policy was found in the repository. That weakens vulnerability-reporting transparency for a dependency, although it is not by itself evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.