Its tests, README, MIT license, and simple dependency profile support routine use. The small project has limited community activity and no documented security process, so future fixes may depend on one maintainer.
60%
Total Score
50
100
83
83
The package has had no registry release for about eight years, with five releases concentrated in October 2018. This is a meaningful maintenance concern, though the repository remained active later and is not archived.
There were no commits and no active maintainers in the last three months. Combined with the old registry release, this indicates a real risk of slow fixes or abandonment.
Two issues remain open, with no issues or pull requests opened or closed in the last month. This is a modest sign of limited ongoing project activity.
The repository has only four stars, two forks, and one watcher, so there is little visible community support to compensate for the thin maintenance activity.
Composer is used for builds, but no security scanning tool is present. The missing scanning is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/collections Version 1.5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.