The package has thorough tests, documentation, and matching MIT licensing, but its single-release history and no commits or active maintainers in the last three months limit confidence in ongoing support. Its large runtime dependency set and four unpinned workflow actions add maintenance and build-integrity concerns.
57%
Total Score
25
50
75
75
There were zero commits and zero active maintainers in the last three months, a concrete sign that maintenance may have slowed or stopped.
The package declares 29 runtime dependencies, including database, administration, and multiple framework bundles; this broad dependency surface increases integration and maintenance burden.
The repository is owned by a user account rather than an organization, so the small project backing does not provide evidence of organizational maintenance capacity.
Only one release exists over about 304 days, so there is little observed release history to demonstrate sustained maintenance.
The repository has zero stars and forks and one watcher, offering little supporting evidence of community review or adoption; popularity is only supporting evidence here.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
nesbot/carbon Version ^2.72 || ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.