Usable with caveats: it is a small, clearly licensed package with a matching repository and security policy, but it has only one release and no commits in the last eight months. The single-maintainer project also has no repository tests or security scanning, so long-term maintenance is uncertain.
58%
Total Score
38
50
78
100
There were zero commits and zero active maintainers in the last three months. For a package with only one release, this is a meaningful maintenance and abandonment concern.
Four runtime dependencies are declared, including two project-specific packages and PSR interfaces; this is a moderate dependency surface rather than an excessive one, though each dependency adds maintenance coupling.
Only one registry account has publishing access, leaving the release process dependent on a single person. The matching personal repository provides some backing but does not remove the continuity risk.
The registry namespace and repository owner match, supporting that the linked repository belongs to this package. It is user-owned rather than organization-backed, so continuity depends on a small owner base.
The package has only one release, first published about eight months ago, so there is little evidence of sustained release maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^2.0 | — | — |
phprise/common-value-object Version ^1.0 | — | — |
phprise/data-transfer-object Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.