It has an MIT license, a focused dependency set, repository tests, and a clear package-to-repository match. The stable release and readable documentation help, but the project shows little evidence of ongoing maintenance.
42%
Total Score
50
100
81
83
The latest release was published in August 2020, and there have been no releases in roughly six years. This is strong abandonment evidence for a dependency, even though the package has only two releases.
Only one registry publishing account is listed, and the project is backed by an individual rather than an organization. That leaves limited visible maintenance capacity if the maintainer becomes unavailable.
Composer build tooling is present, but no security-scanning tools were detected. This is a maintenance and hygiene gap, though it does not by itself show that the release is unsafe.
The linked repository has no security policy. For a package handling database migration behavior, this reduces transparency around vulnerability reporting and maintenance expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/migrations Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.