The package is small, clearly licensed, backed by an organization-owned repository, and has no install-time scripts. Its missing README and security policy reduce transparency, while no release has appeared for over five years.
55%
Total Score
100
83
83
The artifact has no README, which makes integration harder for a library, and the repository also has no tests or changelog. Missing tests and changelogs are normal packaging practice, but the missing consumer documentation remains a transparency gap.
Only three releases exist, with none in the last 12 months; the latest was published over five years ago. This is the strongest evidence of possible maintenance slowdown.
The linked repository has no security policy. This is a modest transparency and reporting gap, though it is less concerning for a small package with no observed release-time scripts.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/serializer Version ^4.0 || ^3.4 | — | — |
google/cloud-pubsub Version ^1.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.