Usable with caveats: the release is licensed, tested, documented, and has a focused dependency profile, but it has had no new release or commit activity for about four years. Very low repository adoption and no security policy add maintenance risk.
58%
Total Score
33
100
72
90
There have been zero commits and zero active maintainers in the last three months, with the repository last pushed about four years ago. This is the main abandonment concern for taking a dependency.
The repository is owned by an individual user rather than an organization, so there is no organizational backing shown to compensate for the thin maintenance evidence.
The package has existed for about 11 years, but it has only three releases and none in the last 12 months; the median release interval is about 3 years 7 months. This indicates very slow maintenance.
There are no open issues or pull requests and no activity in the last month. While a clean tracker can be positive, the complete absence of recent activity is consistent with an inactive project.
The repository has only 1 star, 2 forks, and no watchers. Popularity is supporting evidence rather than a verdict, but these very low adoption indicators provide little external validation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version >=2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.