The MIT license and package/repository name reference make provenance clear. Its dependency set is nontrivial, and the repository has no security scanning, adding smaller maintenance and review concerns.
42%
Total Score
0
50
81
50
The package has had no release in more than six years, despite 33 historical releases. This long publishing gap is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the prolonged release gap and indicating no visible ongoing maintenance.
The package declares four runtime dependencies, including the upstream Doctrine behaviors library it integrates with. This adds dependency coupling but is not by itself a severe adoption risk.
Composer is used for the build, providing standard package tooling, but the repository reports no security-scanning tools, leaving a modest transparency and maintenance gap.
The repository has no security policy, reducing clarity about vulnerability reporting and maintenance response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tracy/tracy Version ~2.7 | — | — |
knplabs/doctrine-behaviors Version ~2.0 | — | — |
contributte/event-dispatcher Version ~0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.