Its README and linked repository make the package identifiable and straightforward to adopt. The MIT declaration conflicts with the BSD-3-Clause license file, and the repository has no security policy.
38%
Total Score
0
58
50
The package has had only two releases, both in June 2016, with no release in nearly ten years. That long gap is strong evidence of abandonment risk.
There were no commits and no active maintainers in the last three months, and the repository was last pushed in June 2016. This is the clearest evidence that maintenance has stopped.
A license file is present, so the release is licensed, but the manifest declares MIT while the artifact license file is detected as BSD-3-Clause. The mismatch reduces transparency.
The repository has zero stars and forks and only three watchers. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of a broad user or contributor base.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, adding concern to an already inactive project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zendframework Version ~2.5 | — | — |
doctrine/doctrine-orm-module Version 0.9.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.