The package includes a clear MIT license, tests, and a complete source tree. Its lack of recent activity and absent security policy reduce confidence in long-term maintenance.
58%
Total Score
50
100
83
88
The source repository is owned by an individual account rather than an organization. That is not inherently unhealthy, but it provides less visible backing than an actively maintained organization-owned project.
The latest release was about 5 years and 6 months ago, with no releases in the past 12 months. The 12-release history shows prior publishing activity, but the current pause is a maintenance concern.
The repository has no new issues or pull requests in the past month and no open work. This is consistent with the long release gap and provides little evidence of active maintenance.
The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but this offers little additional confidence for a package that has also stopped releasing.
Composer is used as the build tool, but no security scanning tools are reported. The missing scanning is a modest hygiene gap and matters more alongside the absent security policy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.4 | — | — |
webit/shipment Version ^3.1.0 | — | — |
symfony/symfony Version ^2.5|^3.0 | — | — |
doctrine/doctrine-bundle Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.