The package includes tests, examples, a useful README, and an organization-backed repository with a steady release history. Its pre-1.0 status, no commits in the last three months, and missing security policy leave more maintenance uncertainty than a mature dependency.
68%
Total Score
75
86
75
The repository shows zero commits and zero active maintainers in the last three months, despite the recent release; this suggests current development activity may be limited.
Composer is used for the build, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no published security policy, so users lack documented guidance for reporting vulnerabilities or receiving security fixes.
This release is not a prerelease, but the latest version remains v0.2.16 rather than a stable major release, so the public API may still change substantially.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^3.8|^4.0 | — | — |
beberlei/assert Version ^2.6|^3.0 | — | — |
psr/http-client Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^7.4 | — | — |
eventsauce/object-hydrator Version 1.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.