The artifact is small and straightforward to consume, with a matching Apache-2.0 license and no install-time scripts. Organization ownership and repository/package alignment provide useful accountability, but longer-term maintenance remains unproven.
67%
Total Score
75
100
86
88
This is a newly published package with one release and no established release cadence, so its maintenance maturity cannot yet be demonstrated.
The repository has no commits in the last three months and no active maintainers recorded; because the package is newly created, this is more a lack of demonstrated maintenance than evidence of a long-term collapse.
Composer is used as the build tool, which fits the package, but no security scanning tool is present; this is a modest transparency gap for a package with no broader maintenance history.
The repository has no security policy. For a tiny metadata-only package this is a minor gap, but it leaves vulnerability-reporting expectations unspecified.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/doctrine-annotations-impl Version ~2.0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.