The MIT license, README, release notes, repository tests, and matching source repository make the package straightforward to inspect. It has no security policy or security scanning, and its small user base provides little supporting evidence.
45%
Total Score
0
75
83
This is the package's only release, published over 10 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a library dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and indicating no current maintenance capacity.
The repository has 3 stars, 0 forks, and 1 watcher, providing little external evidence of broad review or community support. Popularity is supporting evidence only, so this reinforces rather than establishes the risk.
Composer build tooling is present, but no security scanning tools were found. This is a modest transparency and maintenance-hygiene gap rather than a standalone adoption blocker.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. For a database connection library, that is a genuine but secondary concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phossa2/shared Version ^2.0.25 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.