Vortos persistence — Doctrine ORM write repository for DDD aggregates
65%
Total Score
caution
Alpha-only releases, unusually frequent publishing, and all recent commits from one contributor temper otherwise active project signals.
The package contains tests and the repository reports tests, which supports project maturity. The missing README is a minor consumer-transparency gap for an ORM library, while the absent changelog is not concerning because release notes are also absent.
The package has made 342 releases in 162 days, with a median interval of about 2 hours. This shows active publishing but an unusually rapid cadence that can make version selection and change review harder.
One contributor made all 6 commits in the last 3 months, creating concentrated maintenance risk. The organization-owned repository provides some ability to hand maintenance off, so this is caution rather than a severe risk.
Composer is used as the build tool, which fits the Packagist package, but no security-scanning tools were detected. The missing scanning is a modest supply-chain hygiene gap.
The repository has no security policy. This is a transparency and reporting gap, though it does not by itself indicate that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.0 | — | — |
doctrine/dbal Version ^4.0 | — | — |
symfony/cache Version ^7.0 | — | — |
symfony/var-exporter Version ^7.0 | — | — |
vortos/vortos-tenant Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.