It includes tests, a readable README, release notes, and a repository that clearly matches the package. Those positives do not offset the package being deprecated and its source repository archived, so choose an actively maintained alternative.
15%
Total Score
50
100
57
88
Packagist marks the entire package as abandoned, with no replacement named. Package-wide deprecation is a severe adoption risk even though this release is stable.
The linked source repository is archived, which indicates the project is no longer intended for normal ongoing maintenance. A push on July 18, 2026 does not compensate for the archived status.
The package has existed for about 7 years and released twice in the last 12 months, but only three releases overall with a median interval of about 3 years and 3 months. Recent releases are a modest positive, not enough to offset abandonment signals.
All recent commit activity comes from one contributor, leaving the project dependent on a single maintainer. The repository owner is an individual rather than an organization, so there is no provided backing to offset that concentration.
Only one commit was recorded in the last three months, by one active maintainer. This provides little evidence of sustained maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jord-jd/uxdm Version ^6.0 | — | — |
spatie/data-transfer-object Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.