The project has a clear license, focused package contents, repository tests, and a release note for this version. Maintenance has paused recently, while all eight workflow actions are unpinned and the audit found a medium-confidence bot-condition issue.
68%
Total Score
88
100
89
83
The package has existed since 2020 with 11 releases, but only one release in the last 12 months and a median interval of about 178 days indicate a slow cadence.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern despite the recent release and push metadata.
The repository has only 2 stars, 0 forks, and 1 watcher. Low popularity is supporting context rather than a health verdict, especially for a focused package.
The repository has no security policy, leaving reporting and response expectations undocumented. This is a transparency gap, but not severe for this small package.
The workflow audit completed fully and found no untrusted checkout or script-injection paths, with read-only permissions; however, all 8 action references are unpinned and a medium-confidence high-severity bot-condition finding remains.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.13@dev || ^3.0@dev | — | — |
nepada/message-bus Version ^2.0@dev || ^3.0@dev | — | — |
doctrine/persistence Version ^2.5 || ^3.0 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.