Package Health

satag/doctrine-firebird-driver

This is a healthy, actively maintained release with a substantial history since December 2022, 38 releases in the last 12 months, a stable major version, current repository activity, tests, changelog, licensing, and security tooling. The main concerns are that all 97 commits in the last three months came from one contributor, the repository lacks a security policy, and two workflows use pull_request_target; these reduce resilience and workflow-transparency confidence but do not outweigh the strong maintenance and release evidence. It is a reasonable dependency, with normal supply-chain review of its GitHub Actions and maintainer continuity still advisable.

Latest v4.7.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

Two of five analyzed workflows use pull_request_target, which warrants review because that trigger can expose elevated repository context to pull-request handling. However, no untrusted checkout or script-injection findings were detected.

Repo bus factorcaution

Only one contributor made all 97 commits in the last three months, creating a genuine continuity and bus-factor concern. Organization ownership provides some potential handoff capacity, but no second active contributor is shown by this signal.

Repo popularitycaution

The repository has only 3 stars and 1 fork, indicating limited external adoption; this is supporting caution rather than a health verdict because the package shows strong direct maintenance activity.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented. Other security tooling partially compensates for this transparency gap but does not eliminate it.

Token permissionscaution

Four workflows lack top-level permissions declarations, although none declares top-level write permissions and four use job-level permissions while one is read-only. The absence of explicit top-level defaults is a workflow-hardening gap, not evidence of excessive granted access.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Michael Wegener
Kasper Søfren
Uffe Petersen

Direct Dependencies

DependencyLast ReleaseScore
doctrine/dbal
Version ^4.4
—
—
symfony/polyfill-php83
Version ^1.33
—
—
symfony/polyfill-php84
Version ^1.33
—
—
symfony/polyfill-php85
Version ^1.33
—
—
symfony/polyfill-intl-grapheme
Version ^1.33
—
—

Weekly Downloads

Info

Last Published
20 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform