Usable with caveats: Phinx is a mature, licensed package with a clear repository, tests, documentation, and a long release history. However, the linked repository has had no commits or active maintainers in the last three months and lacks a security policy, so verify that its maintenance pace meets your needs.
62%
Total Score
67
100
89
83
The repository recorded zero commits and zero active maintainers over the last three months, a meaningful sign that maintenance may have slowed or stopped.
There were no new or merged pull requests in the last month, and issue counts are partly unavailable; this provides little evidence of active project support.
The linked repository has only 2 stars and 1 fork, which is weak supporting evidence, though popularity alone does not determine whether a mature package is safe to depend on.
Composer and Box provide build tooling, but no security scanning tools were detected, leaving a security-transparency gap.
The repository has no SECURITY.md or other detected security policy, making vulnerability reporting and response expectations less clear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^4.0|^5.0|^6.0|^7.0 | — | — |
symfony/config Version ^4.0|^5.0|^6.0|^7.0 | — | — |
symfony/console Version ^4.0|^5.0|^6.0|^7.0 | — | — |
vlucas/phpdotenv Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.