Its tiny repository footprint and absent security controls add transparency concerns. The README and stable 1.0.9 metadata are useful, but not enough to offset the maintenance gap.
42%
Total Score
0
100
72
75
The latest release was about 21 months ago, with no releases in the last 12 months. Seven releases arrived early in the project's life, but the long pause indicates abandonment risk.
The repository had no commits and no active maintainers in the last 3 months, reinforcing the extended release gap and leaving little evidence of ongoing maintenance.
The package declares no license, contains no license file, and the repository has no license file. This creates a concrete legal and adoption risk for developers.
The repository has only 4 stars, 0 forks, and 1 watcher. Low popularity is supporting evidence rather than decisive on its own, but it offers little external validation for a package already showing inactivity.
Composer is used for the build, which is appropriate, but no security scanning tools are configured. That weakens supply-chain transparency without proving the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mage/db2 Version ^1 | — | — |
mage/view-table Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.