The MIT license, detailed README, and repository tests make the code easier to evaluate. Its workflow audit found no dangerous sinks, but the project lacks current maintenance and should be replaced with jolicode/automapper.
10%
Total Score
0
40
50
Packagist marks the entire package as abandoned and names jolicode/automapper as its replacement, making this release unsuitable for a new dependency.
The package has 73 releases since April 2018, but its latest release was July 10, 2023 and it had no releases in the following 12 months, showing that activity has stopped.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the archived and abandoned project state.
The linked repository is archived, with its last push on December 2, 2023; archived source is a severe abandonment risk.
The single workflow was fully analyzed with no audit findings or untrusted checkout and script-injection sinks. Its one unpinned action is a minor reproducibility concern, and the pull_request_target trigger is not dangerous on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^4.0 | — | — |
doctrine/inflector Version ^1.4 || ^2.0 | — | — |
symfony/serializer Version ^5.1 || ^6.0 | — | — |
symfony/property-info Version ^5.3 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.