The package has a clear README, repository tests, release notes, an MIT license, and no install-time scripts. Its one-person ownership, absent recent activity, missing security policy, and unpinned workflow actions leave meaningful maintenance and build-integrity concerns.
58%
Total Score
50
100
92
67
One registry maintainer is consistent with the matching user-owned repository, but it leaves little visible publishing redundancy or bus-factor protection.
The repository is owned by the same individual namespace that publishes the package, providing direct ownership alignment. It is user-backed rather than organization-backed, so there is limited institutional continuity.
Only two releases exist, with the latest published about 14 months ago and no releases in the last 12 months. That limited and currently stalled release history raises abandonment risk.
The repository recorded no commits and no active maintainers during the last three months, consistent with the long gap since the latest release. This is a meaningful maintenance concern for a library dependency.
Five issues remain open while there was no issue or pull-request activity in the last month. The lack of recent response adds to the evidence of slow maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.0 || ^4.0 <4.3 | — | — |
marcj/topsort Version ^2.0 | — | — |
psr/container Version ^2.0 | — | — |
symfony/console Version ^5.4 || ^6.0 || ^7.0 | — | — |
doctrine/persistence Version ^3.1|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.