The project has tests, release notes, organizational backing, and a recent repository push. Its release stream has paused for over a year, while all 13 workflow actions are unpinned and no security scanning or policy is present.
68%
Total Score
67
50
88
75
The package declares 14 runtime dependencies, including PHP and MongoDB extensions, creating a moderately broad compatibility surface for a framework integration module.
The package has 41 releases since 2012, but none in the last 12 months and the latest registry release was over a year ago. This raises maintenance concern, although the repository was pushed recently and the release history is substantial.
The repository recorded zero commits and zero active maintainers in the last three months. A recent repository push partly offsets this, but the short-term development pause remains a maintenance concern.
There are no open issues and only one open pull request, with no issue or pull-request merges in the last month. This is consistent with low current activity but is not severe on its own.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/cache Version ^2.0.0 | — | — |
symfony/console Version ^6.3.2 || ^7.0.0 | — | — |
symfony/var-dumper Version ^6.3.2 || ^7.0.0 | — | — |
laminas/laminas-mvc Version ^3.6.1 | — | — |
doctrine/mongodb-odm Version ^2.5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.