The source repository is active and well-scaffolded, with tests, release notes, and read-only workflow permissions. A single-contributor history, license mismatch, and unpinned actions add adoption risk.
20%
Total Score
75
71
50
Packagist marks the entire package as abandoned and names innobrain/laravel-openimmo as a replacement, making this release a poor dependency choice despite other healthy repository signals.
The artifact includes a license file, but it is detected as GPL-3.0 while the manifest declares MIT; that unresolved mismatch creates legal and adoption uncertainty.
The package has had seven releases, but none in the last 12 months and its latest registry release was about 19 months ago, indicating a stalled release line.
All seven commits in the last three months came from one contributor, leaving maintenance dependent on a single person; organization ownership provides some handoff capacity but does not remove the concentration risk.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jms/serializer Version ^2.1 || ^3.5 | — | — |
symfony/serializer Version ^5.3 || ^6.0 | — | — |
doctrine/annotations Version ^2.0 | — | — |
illuminate/contracts Version ^10.0||^11.0 | — | — |
goetas-webservices/xsd2php Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.