The package is small, documented, and includes tests and Psalm-based security scanning. Maintenance has slowed, and the workflow uses unpinned actions; pinning a maintained release should be part of adoption planning.
60%
Total Score
50
93
50
One registry publishing maintainer is a thin publishing base for a user-owned project. This raises continuity risk, although the linked repository is active enough to provide direct project ownership context.
There have been no releases in the last 12 months, and the median interval between releases is about 658 days. The latest release is still recent enough to avoid an abandonment verdict, but the cadence is slow.
The repository recorded no commits and no active maintainers in the last three months. Its last push coincides with the latest release, so there is limited evidence of ongoing maintenance beyond that release.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both analyzed action references are unpinned. This is a supply-chain hygiene gap rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vimeo/psalm Version ^4.0 || ^5.0 || ^6.0 | — | — |
doctrine/mongodb-odm Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.