The package is clearly documented for its narrow metapackage role and carries matching Apache-2.0 licensing. Its organization-backed repository is present, but maintenance history is too short to establish reliability; pinning this exact version is sensible.
62%
Total Score
75
100
86
50
The package is 0 days old with one release and no established release cadence. This is not evidence of abandonment, but it leaves ongoing maintenance unproven.
The repository records 0 commits and 0 active maintainers over the last 3 months. Because the package is newly published, this mainly reflects unproven maintenance capacity rather than established abandonment.
Composer build tooling is present, but no security scanning tools were detected. For this small package that is a hygiene gap, not a severe supply-chain concern.
The repository has no security policy. This reduces vulnerability-reporting transparency, though the package's narrow metapackage role limits the practical impact.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/doctrine-dbal-impl Version ~4.4.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.