Package Health

kenny1911/doctrine-dbal-hydrator

The repository includes a focused test suite, a clear MIT license, and release notes for this version. Its workflow leaves all seven actions unpinned, increasing build-integrity risk.

Latest 0.1.2PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package is 431 days old with three releases, only one in the last 12 months, and a median interval of about 130 days. The recent 0.1.2 release provides some evidence of activity, but the overall cadence is thin.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the past three months. That recent inactivity is a meaningful maintenance concern despite the release pushed at the start of the collection period.

Security policycaution

The repository has no security policy. For a library that handles database results and typed object conversion, this reduces the project's documented process for reporting and handling security issues.

Version stabilitycaution

Version 0.1.2 is not a prerelease, but the package remains below 1.0, so compatibility and maturity are less established than for a stable-major release.

Workflow auditcaution

The single workflow was fully analyzed with no untrusted checkout or script-injection findings, and no top-level write permissions were used. However, all seven action references are unpinned, leaving the build exposed to changing action contents.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Kenny1911

Direct Dependencies

DependencyLast ReleaseScore
doctrine/dbal
Version ^3.0 || ^4.0
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform