The package includes a README, tests, a matching GPL-3.0 license, and organization backing. Its old dependency stack, install-time scripts, and missing security policy add maintenance and transparency concerns.
38%
Total Score
50
79
67
There has been only one release, published nearly 11 years ago, with no releases in the last 12 months. This strongly indicates the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long gap since its last push. No provided signal shows current maintenance to offset this.
The package defines post-install and post-update Composer scripts, so installation and updates execute package-provided code. This is an additional supply-chain exposure for a package that is otherwise already difficult to trust as maintained.
Composer is used as the build tool, but no security-scanning tooling is reported. The absence of scanning is a modest transparency gap rather than evidence that the release is unsafe.
The linked repository has no security policy. This weakens vulnerability-reporting transparency, with no provided evidence of security scanning or another process that compensates for the gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ~2.5 | — | — |
doctrine/dbal Version ~2.5 | — | — |
symfony/symfony Version 2.7.* | — | — |
mandango/mandango Version 1.0.*@dev | — | — |
mandango/mondator Version 1.0.*@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.