The package is small and easy to inspect, with a clear MIT license and usage README. Its single maintainer and absent security scanning leave little evidence of ongoing stewardship. Pin this only if its unchanged API meets your needs.
40%
Total Score
25
79
83
The package has had only two releases, both in October 2018, with no release in roughly eight years. This is strong evidence of abandonment risk for a library dependency.
The repository has recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap and providing no evidence of current maintenance.
One registry maintainer account is responsible for publishing the package. This is not inherently unhealthy, but it leaves a thin publishing base alongside the absence of recent activity.
Composer is used for the build, but no security-scanning tooling is present. That reduces automated assurance, although it is less significant than the long maintenance gap.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This is a transparency gap for a database-access library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.