Clear documentation, tests, and licensing make integration straightforward. The small project footprint, quiet recent activity, and absent security policy leave less evidence for long-term support.
72%
Total Score
83
100
89
83
The package has four releases over about 18 months, with only one release in the last 12 months; this suggests a modest and recently slower release cadence.
There were no commits and no active maintainers in the three months measured, which is a concrete sign of quiet recent maintenance for a relatively young package.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance-hygiene gap.
The repository has no security policy, so consumers have no documented reporting or response process if a vulnerability is found.
Both workflows were analyzed without audit findings or dangerous triggers, and one uses read-only permissions. However, all three analyzed action references are unpinned, which weakens build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.0 | — | — |
doctrine/dbal Version ^4.0 | — | — |
doctrine/common Version ^3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.