The package has clear licensing, substantial tests, release notes, and a repository that matches the package. Its small publishing base and absent security policy add modest concerns alongside the recent maintenance slowdown.
68%
Total Score
63
100
88
88
Only one account has registry publishing access, which is a modest operational concentration. The repository is organization-owned, so the short registry maintainer list is not by itself evidence of weak project backing.
The package has existed for about 11 years with 25 releases, but has had no releases in the last 12 months. The long history is reassuring, while the recent pause lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months. That is a meaningful maintenance concern, especially combined with no registry releases in the last 12 months.
There are six open issues and three open pull requests, but no new or closed issues or pull requests in the last month. This suggests limited recent project interaction.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanner is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.0 | — | — |
doctrine/dbal Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.