Define a specification of PHP entity and check whether the particular item matches it.
45%
Total Score
unhealthy
No registry release since 2018 and no repository commits in over five years indicate strong abandonment risk.
The latest release was in April 2018, more than 8 years ago, with no releases in the last 12 months. This is strong evidence of stagnation for a dependency, despite the package having a stable release history rather than chaotic versioning.
There were no commits and no active maintainers in the last 3 months. Combined with the last registry release being over 8 years ago, this indicates prolonged abandonment risk.
The repository is owned by an individual user rather than an organization, so there is no visible organizational backing to compensate for the thin maintenance history.
Composer is used as the build tool, but no security-scanning tools are present. The missing scanning is a hygiene gap rather than evidence that the package is unfit by itself.
The repository has no security policy. This reduces transparency about vulnerability reporting and response, especially for a package that has seen no recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/annotations Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.