The five-file wrapper is deliberately small, and its MIT license and organization ownership improve transparency. Check that its sole Doctrine dependency remains maintained before pinning this old release.
55%
Total Score
75
100
79
83
Only two releases were published, both in August 2025, with no release in the following 12 months. That leaves this version without evidence of ongoing release maintenance.
There were zero commits and zero active maintainers in the last three months. Combined with the long release gap, this is concrete evidence of currently inactive maintenance.
The repository name does not match the package name and its README does not mention the package, so the link is not clearly established by repository content. Organization ownership provides some context but does not remove this concern.
Composer is used as the build tool, which fits a PHP package, but no security scanning tools were detected. The missing scanning is a modest transparency gap for a small project.
The repository has no security policy. This is a hygiene and disclosure gap, though the package is a small configuration wrapper with no indication of security-sensitive behavior.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
martin-georgiev/postgresql-for-doctrine Version ^3.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.