Risky to depend on: this package has had no release or repository activity for about 10 years. It is not deprecated or archived, but its minimal two-file project and missing README leave little evidence of ongoing maintenance or consumer support.
35%
Total Score
0
71
67
The package has only one release, published about 10 years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a dependency that may need compatibility or security maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history showing no activity for about 10 years. The repository is not archived, but it shows no practical maintenance capacity.
Both the package and repository contain only composer.json and one serializer source file. The small implementation may be intentional, but the extremely limited project structure provides little transparency or evidence of broader maintenance practices.
The artifact has no README, while tests and changelog files are not expected in a published package; the repository also has no tests or changelog. Missing consumer documentation is a real usability gap, although the GitHub release and matching repository provide some context.
Composer is used as the build tool, which is appropriate for this PHP package, but no security scanning tooling is present. Given the repository's long inactivity, there is no visible automated safeguard compensating for the lack of maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.