The project has one registry maintainer, no security policy, and no repository security scanning, which limits oversight. Its small dependency set, tests, license, and release notes provide useful transparency.
63%
Total Score
50
100
89
50
Only one account has registry publishing access, leaving the release process dependent on a single person; the repository's individual ownership makes this a real but moderate resilience concern.
The package and repository are owned by the same individual account, providing consistent ownership context but no organizational backing or maintainer redundancy.
No commits and no active maintainers were observed in the last three months, indicating recently quiet development even though the package has a substantial release history.
The repository has zero stars and forks and one watcher, providing little independent adoption evidence; popularity is supporting evidence, so this lowers confidence more than it determines health.
Composer build tooling is present, but no security scanning tool was detected, leaving automated vulnerability oversight limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.0 | — | — |
juniwalk/orm Version >=3.1.1 <4.0 | — | — |
juniwalk/utils Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.