It includes tests, release notes, and a matching MIT license, with no install-time scripts. The repository is small and has no security policy, while all three workflow actions are unpinned, limiting maintenance and build-supply-chain confidence.
67%
Total Score
50
100
92
67
The repository recorded zero commits and zero active maintainers in the last 3 months. Although the same period includes a new release, the lack of ongoing commit activity is a maintenance concern.
Composer is used for the build, but no security scanning tool was detected. The missing scanner is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy. This weakens vulnerability-reporting transparency for a library intended to be integrated into applications.
The single workflow was fully analyzed with no audit findings or untrusted checkout and script-injection issues. However, all 3 of its action references are unpinned, leaving them exposed to upstream reference changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^2.5|^3.3|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.