GCWorld Industries ORM
78%
Total Score
75
100
80
The package uses a post-autoload-dump Composer script. This is an install-time behavior that deserves review, but the available package structure and documentation indicate it is part of the documented Composer installer workflow rather than unexplained behavior.
No commits and no active maintainers were recorded in the last three months, which is a genuine maintenance concern. However, the registry shows 16 releases in the last year and the repository was pushed at the assessed release, partially offsetting the signal.
The repository has no security policy. This is a transparency gap for a package that handles database-backed models, although automated dependency scanning and audit tooling provide partial compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.9 | — | — |
symfony/yaml Version ^6.4 | — | — |
gcworld/common Version ^2.7 | — | — |
gcworld/globals Version ^4.0 | — | — |
monolog/monolog Version ^3.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.