Repository pattern for PHP — generic CRUD with raw-data access, read/write splitting, and pluggable primary-key strategies; the persistence layer Jardis-generated repositories build on
72%
Total Score
caution
Active releases and tests are offset by one-contributor maintenance and workflow hygiene gaps.
All 11 recent commits came from one contributor, creating concentrated maintenance risk. Organization backing provides some handoff capacity but does not remove the current single-contributor dependence.
The repository has no security policy, which leaves vulnerability-reporting expectations undocumented and reduces transparency for a persistence library.
All seven action references are unpinned, and the audit found one high-confidence template-injection issue plus a script-injection finding in the release workflow; the top-level write permission increases exposure. The workflows were fully analyzed, but these release-automation gaps warrant caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jardissupport/dbquery Version ^1.0 | — | — |
jardissupport/contracts Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.