Tests, licensing, and a matching organization-owned repository provide useful baseline confidence. The project has no demonstrated release or commit history yet, and repository security safeguards are limited.
68%
Total Score
75
100
86
88
This is the package's first release, published today, so there is no release track record to establish maintenance or stability. Its newness explains the gap but does not remove the maturity uncertainty.
There were zero commits and zero active maintainers in the last three months, leaving no observed history of ongoing maintenance. Because the repository was created immediately before this first release, this is an immaturity caution rather than strong abandonment evidence.
Composer is used for the build, but no security scanning tools were detected. For a newly published package this limits automated assurance, though it is not a severe dependency risk by itself.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations. This is a hygiene and maturity gap, not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version 4.4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.