Usable with caveats: the release is documented, tested, licensed, and not deprecated or archived. However, it has only one release, no commits in the last three months, a single maintainer, and no repository security policy, so long-term support is uncertain.
58%
Total Score
63
100
89
88
Only one registry publishing account is listed. This is consistent with an individual-owned project, but it leaves limited demonstrated publishing redundancy.
The package and repository are backed by the same individual rather than an organization, so there is no organizational continuity signal to offset the thin maintainer base.
The package is about 9 months old but has only one release, with no subsequent release activity to demonstrate an established maintenance cadence.
The repository recorded zero commits and zero active maintainers in the last 3 months, which is the clearest sign that maintenance may have stalled.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest security-process gap for a database-facing library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.