The repository has had no commits for over five years, and the package README says development has ended and points users to alternatives. Its small, unchanged codebase and missing repository package reference add uncertainty about continued support.
18%
Total Score
0
40
The package includes a README, but it explicitly says the bundle is deprecated in practice, will receive no further development, and recommends alternatives or self-maintenance. That is a severe abandonment warning for a dependency.
The package has had no release in over five years: its latest release was July 2021, with zero releases in the last 12 months. This strongly indicates the release line is no longer maintained.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the README's statement that development has stopped.
The linked repository name does not match the package name and its README does not mention this package. For a dependency, that weakens confidence that the source repository is the authoritative project.
The assessed version is 3.0.0 while the registry reports 2.2.0 as the latest version, creating uncertainty about the release metadata and supported version line.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/common Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.