The dependency surface is small, and the repository uses Composer and Psalm without detected dangerous workflow patterns. Its organization backing and package-name match add context, but do not offset the maintenance risk.
12%
Total Score
100
100
50
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because the registry explicitly signals that the package is no longer maintained.
The package has had only three releases, all concentrated on June 15, 2022, with no releases in the last 12 months. This supports a strong abandonment concern rather than an actively maintained release line.
The linked repository is archived and was last pushed in June 2022. An archived source repository indicates the project is no longer expected to receive maintenance.
The artifact contains no README, tests, or changelog, while the repository also reports no tests or changelog. These are transparency and validation gaps for a library, although the repository file tree does contain a README.
The repository has no security policy. This is a secondary transparency gap, especially for a serialization library, but it is outweighed by the package's abandonment status.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.