The MIT license, readable setup guide, and release notes make adoption easier. The small project has no security policy and only one publisher, limiting confidence in long-term support.
58%
Total Score
50
79
75
Only one registry account has publishing access. That is a limited publishing base for a user-owned project and increases continuity risk when combined with inactive recent releases.
The package has had no registry release in over three years, with five releases total and none in the last 12 months. That is a meaningful maintenance concern for a framework integration.
The repository recorded zero commits and zero active maintainers in the last three months. This is consistent with a project that may be dormant, despite the repository not being archived.
Composer build tooling is present, but no security scanning tooling was detected. For a small PHP bundle this is a modest transparency and maintenance gap, not a severe risk.
The linked repository has no security policy. This weakens disclosure guidance and project transparency, although it does not by itself show unsafe code or abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.5 | — | — |
doctrine/migrations Version ^3.5 | — | — |
doctrine/doctrine-bundle Version ^2.8 | — | — |
symfony/framework-bundle Version ^6.2 | — | — |
pfilsx/postgresql-doctrine Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.