The package has no license information and no documented security policy, which makes long-term use and review harder. Its tests, README, organization backing, and matching repository provide useful context, but do not offset the age of the project.
38%
Total Score
67
75
75
No declared license, recognized license text, or license file was found in the package or repository. That creates a real adoption and redistribution concern.
The package has had no releases in the last 12 months, and its latest release was more than 11 years ago. Seventeen historical releases show prior activity but do not offset the current abandonment risk.
There were no commits and no active maintainers in the last three months, consistent with a repository whose last push was more than 11 years ago. This is strong evidence of abandonment risk.
There were no new or closed issues or pull requests in the last month, with no open issues or pull requests. This is consistent with inactivity rather than evidence of active support.
The repository has only 2 stars and 5 forks, indicating limited visible adoption. Popularity is supporting evidence, so this reinforces but does not determine the maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zoopcommerce/shard Version ~5.0 | — | — |
doctrine/annotations Version dev-master#a11349d39d85bef75a71bd69bd604ac4fb993f03 as dev-master | — | — |
doctrine/mongodb-odm Version dev-hotfix719 as 1.0.0-BETA9 | — | — |
zoopcommerce/juggernaut Version ~1.1 | — | — |
doctrine/doctrine-module Version 1.0.x-dev as 1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.