The stable API, MIT license, tests, and matching organization repository provide useful transparency. Its small dependency footprint is reassuring, but not enough for a new dependency.
20%
Total Score
75
100
75
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on it.
A post-autoload-dump install-time script runs during dependency installation. This adds execution surface for consumers, though the signal provides no evidence that the script is harmful.
This is the only release, published in August 2022, with no releases in the last 12 months. The lack of release history indicates a largely inactive package.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long period without a release. This raises abandonment risk.
The linked repository has no security policy. That weakens vulnerability-reporting transparency, although it is secondary to the package's abandonment status.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bizcommerce/data-object Version ^1.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.