The package has a clear license, source repository, tests, and changelog. Security policy and automated security scanning are absent, while maintenance activity has stopped, so future compatibility and fixes are uncertain.
57%
Total Score
75
88
83
The package has 22 releases and a stable 5.0.1 version, but it has had no releases in the last 12 months and its latest release was about 3 years 8 months ago. This materially raises abandonment and compatibility risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long gap since the latest release. This weakens confidence that defects or dependency changes will be addressed.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest repository-hygiene gap rather than a severe risk.
The repository has no security policy. That reduces transparency around vulnerability reporting and response, although it is not evidence of a security defect by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
atlas/orm Version 3.1.1 | — | — |
psr/cache Version 2.0.0 | — | — |
twig/twig Version 3.5.0 | — | — |
filp/whoops Version 2.14.6 | — | — |
doctrine/orm Version 2.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.