The repository has had no commits or releases for about four years and nine months, and it has no security policy. The package is documented, licensed, stable, and has a matching repository with tests, so pin this version if its unchanged dependencies remain suitable.
58%
Total Score
50
100
81
75
The repository is owned by a user account rather than an organization, so the single registry maintainer does not benefit from visible organization backing. This provides limited continuity evidence but is not abandonment proof.
The package has only two releases, with no release in about four years and nine months and none in the last 12 months. This indicates limited ongoing maintenance, though a small stable library may not need frequent releases.
There were no commits and no active maintainers in the last three months. Given the repository's age, this is evidence of stopped rather than merely slow recent development.
There are no open issues or pull requests and no recent issue or pull request activity. This is consistent with a quiet project but does not by itself demonstrate active maintenance.
The repository uses Composer build tooling but has no detected security scanning tools. The missing scanning is a modest transparency and hygiene gap, not a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jms/serializer Version ^3.0 | — | — |
bluepsyduck/laminas-autowire-factory Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.