The repository matches the package and contains tests, a README, and a declared MIT license. Its single-maintainer setup, absent security policy, and negligible repository activity leave limited evidence of long-term support.
58%
Total Score
50
69
75
The latest release was published in May 2016, with no releases in the last 12 months and only four releases overall. The repository was pushed recently, but the long gap in published versions is a meaningful maintenance concern for consumers.
Only one registry account has publishing access, which limits publishing continuity if that maintainer becomes unavailable. The linked repository is owned by the same individual, so there is no organizational backing shown to offset that concentration.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little independent evidence of broad adoption or community support.
Composer is used as the build tool, but no security-scanning tools were detected. The missing scanning is a hygiene gap, while the standard build tooling supports reproducible project setup.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This lowers transparency but is not severe enough to make the release unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.5 | — | — |
doctrine/dbal Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.