The source repository is active enough to remain unarchived and includes tests, documentation, and release notes. Recent commit activity has stopped, and workflow dependencies are unpinned, adding maintenance and build-integrity concerns.
35%
Total Score
50
70
75
Packagist marks the entire package as abandoned and points to faapz/pdo as a replacement. This is a major adoption risk even though the specific release is stable.
The latest registry release was in November 2021, with no releases in the last 12 months; the package has gone nearly five years without a registry update. The 24-release history shows prior development but does not offset the long gap.
The repository recorded no commits and no active maintainers in the last three months. Although the repository was pushed in April 2025, the recent inactivity still raises maintenance concerns.
The repository has no security policy, making vulnerability reporting less transparent for a database library. This is a secondary concern because the source, tests, and documentation are present.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings. However, all three referenced actions are unpinned, leaving a modest build-integrity weakness.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.