Usable with caveats: the package is clearly identified, licensed, documented, and backed by an organization, but it has had no release or repository activity since February 2019. Its very small codebase and lack of tests or security tooling increase the maintenance risk for a production dependency.
56%
Total Score
75
100
83
83
This package has only one release, published about 7 years ago, with no releases in the last 12 months. That is strong evidence of a stagnant project, although the narrow scope may reduce the need for frequent releases.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. No newer activity is provided to compensate for this lack of maintenance evidence.
Composer is used for builds, but the repository reports no security scanning tools. This is a modest transparency and maintenance gap, though the absence of workflows also limits workflow-related exposure.
The repository has no published security policy. For a package intended to process database exports, this reduces transparency around vulnerability reporting, although it is not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fzaninotto/faker Version ~1.4 | — | — |
ifsnop/mysqldump-php Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.