Clear licensing and a matching repository make the package easy to trace and adopt. The organization provides some continuity, but security tooling and a security policy are absent.
72%
Total Score
67
94
75
All recent repository commits came from one contributor. Organization ownership offers some handoff capacity, but no second active contributor is shown to offset the concentration.
Only one commit was recorded in the last three months, so recent development activity is thin despite the recent release history. This is a maintenance concern, not evidence of abandonment on its own.
Composer is used for the build, but no security-scanning tool was detected. That leaves a transparency and maintenance-hygiene gap for a dependency library.
The repository has no security policy, so users are given no documented process for reporting or handling security issues. This is a transparency gap rather than a direct safety verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.7 | — | — |
doctrine/dbal Version ^3.8 || ^4.0 | — | — |
doctrine/collections Version ^3.1 | — | — |
symfony/polyfill-php86 Version ^1.37 | — | — |
rekalogika/rekapager-contracts Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.