This is the PostgreSQL MDB2 driver.
68%
Total Score
67
88
75
The artifact declares BSD-2-Clause but its license file is detected as BSD-3-Clause. A license file exists, so this is a mismatch requiring clarification rather than an unlicensed-release concern.
One contributor made all four commits in the last three months. Organization ownership provides some handoff capacity, but no second recently active contributor is shown.
The repository recorded four commits in three months, showing recent activity, but all activity came from one active maintainer.
Composer is used as the build tool, but no security-scanning tooling is reported. This is a modest transparency and maintenance gap for a dependency package.
The repository has no security policy. That leaves vulnerability reporting and response expectations undocumented, though it is not evidence of a vulnerability by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverorange/mdb2 Version ^3.2.0 | — | — |
pear/pear-core-minimal Version ^1.9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.