The package includes tests, a clear README, and release notes, which make its behavior easier to evaluate. Its long inactivity means compatibility and maintenance problems may go unresolved; avoid adding it to new projects unless its old API is specifically required.
42%
Total Score
50
71
50
The package has had only 2 releases, with none in the last 12 months, and its latest release was in July 2018. This is strong evidence of abandonment risk for a dependency handling database transactions.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, with its last push in July 2018. This indicates that defects or compatibility issues are unlikely to receive timely fixes.
The repository uses Composer build tooling, which supports reproducible package management, but it reports no security scanning tools. The missing scanning is a modest hygiene concern rather than evidence that the package is unsafe.
The repository has no security policy, leaving no documented path for reporting vulnerabilities or handling security issues. This is a transparency gap, although it is secondary to the much stronger abandonment signal.
Version 0.1.1 is not a stable major release, so compatibility guarantees are limited. The absence of prerelease labeling is mildly positive but does not offset the package's age and inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mongodb/mongodb Version >=1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.