Usable with caveats: it has a current stable release, clear documentation, extensive tests, and active repository maintenance signals. The main concerns are a single maintainer, no commits in the last three months, and limited repository security controls.
68%
Total Score
75
100
89
80
Only one registry account has publishing access, creating a meaningful continuity and bus-factor concern. The linked repository is user-owned rather than organization-backed, so there is no provided organizational support signal to offset it.
The repository recorded zero commits and zero active maintainers in the last three months, despite a recent release and merged pull requests. This creates a maintenance-continuity concern because current development activity is not consistently visible.
The repository has zero stars and forks and only one watcher, so there is little community adoption evidence. Popularity is supporting evidence rather than a decisive health measure, and the repository shows other maturity signals.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap, though it is not by itself evidence that the package is unsafe or abandoned.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented. This is a transparency gap for a database connectivity library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.