The small codebase has a clear README, matching repository, stable version, and no install scripts. The sole maintainer, absent security policy, and no activity since January 2022 make long-term support uncertain; verify compatibility before pinning.
55%
Total Score
50
72
75
The artifact and repository both contain a license, but the declared AGPL-3.0-or-later differs from the detected GPL-3.0 text. The package is licensed, but the mismatch warrants checking compatibility.
The package has 22 releases, but its latest release was December 28, 2021, with no releases in the last 12 months. That long gap is a meaningful maintenance concern, though the repository is not archived.
There were no commits or active maintainers in the last three months, consistent with the repository's last push in January 2022. This materially increases abandonment risk.
The repository has zero stars and forks and only one watcher, indicating very little visible community backing. Popularity is supporting evidence, but this does not independently make the package unfit.
The repository uses Composer, but no security-scanning tooling is present. That is a modest transparency and maintenance gap for a package handling database connections.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.