The package includes tests, a readable README, and no install-time scripts. It is not deprecated or archived, but the evidence provides little support for ongoing compatibility or security upkeep.
35%
Total Score
0
63
75
The package has had 5 releases, but none in the last 12 months; its latest release was in April 2017, roughly 9 years ago. This strongly raises abandonment and compatibility risk.
There were no commits and no active maintainers in the last 3 months, consistent with the repository having been inactive since 2017. This is substantial evidence of abandonment risk.
A license file is present and the repository also has one, but the manifest declares MIT while the artifact license file is recognized as BSD-2-Clause. That mismatch needs clarification before adoption.
Composer build tooling is present, but no security scanning tools were detected. For an old dependency with no recent activity, the missing security tooling is a transparency and upkeep gap.
The linked repository is not archived, which is a positive maintenance indicator. However, its last push was in July 2017, so the non-archived status does not compensate for the long inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/data-fixtures Version v1.2.2 | — | — |
doctrine/doctrine-orm-module Version ~1.1.1 | — | — |
zendframework/zend-eventmanager Version 2.* | — | — |
zendframework/zend-modulemanager Version 2.* | — | — |
zendframework/zend-servicemanager Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.