The repository has tests, a matching README, and a clear MIT license. However, the last release was over 11 years ago and the repository has had no recent commits or active maintainers; security scanning and a security policy are also absent.
38%
Total Score
50
100
72
88
The package has had only two releases, with the latest over 11 years ago and none in the last 12 months. This strongly indicates long-term inactivity, with no newer release evidence to compensate for it.
There were no commits and no active maintainers in the last three months, consistent with the long release gap. This is strong evidence that maintenance capacity has effectively disappeared.
There were no new or closed issues or pull requests in the last month, and no open issues or pull requests. Together with the inactive commit history, this supports an abandonment concern rather than showing active maintenance.
The repository has one star and no forks, so there is little community evidence to support ongoing maintenance or rapid issue resolution.
Composer is used for builds, but no security scanning tools are present. The build tooling is appropriate, while the missing scanning provides a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/common Version ~2.4 | — | — |
stefanotorresi/thorr-persistence Version ~1.0@beta | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.