Documentation is present, and the repository is active rather than archived. The project has no security policy or repository security scanning, and its single release provides little evidence of sustained maintenance.
62%
Total Score
50
100
88
88
The source repository is owned by an individual account rather than an organization. That is not inherently unhealthy, but it provides less visible institutional backing.
This is the package's only release, published 0 days ago, so there is no observed release cadence or maintenance history yet.
Composer is used for builds, but no repository security scanning tools were detected, leaving a meaningful supply-chain hygiene gap.
The repository has no SECURITY.md or other detected security policy, reducing transparency for vulnerability reporting and maintenance expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^4.0 | — | — |
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
doctrine/migrations Version ^3.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.