Lightweight ORM with attribute-based relations for Neuron-PHP framework
72%
Total Score
caution
Active releases and organization backing are offset by one active contributor and three unpinned workflow actions.
All six recent commits came from one contributor, creating a meaningful single-maintainer continuity risk; organization backing provides some ability to hand off maintenance.
Composer build tooling is present, but no security-scanning tools were detected, leaving a security-process gap.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a database component.
Version 0.1.15 is not a stable major release, but it is not marked as a prerelease and recent releases show consistent versioning.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but all 3 referenced actions are unpinned and the workflow lacks a top-level permissions block.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
neuron-php/cli Version 0.8.* | — | — |
neuron-php/core Version 0.8.* | — | — |
neuron-php/data Version 0.9.* | — | — |
robmorgan/phinx Version ^0.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.