A clear README, tests, matching MIT license, and small dependency set make the package easy to inspect. Its long silence and single-person ownership make future fixes uncertain.
58%
Total Score
50
100
88
75
Only one account has registry publish access. This is not evidence of unsafe registry administration, but it leaves limited visible publishing capacity for a user-owned project.
The repository is owned by a user account rather than an organization, so the single visible registry maintainer represents a genuinely thin project backing rather than ordinary organization publishing hygiene.
The latest release was published about 3 years and 7 months ago, with no releases in the last 12 months. The six-release history shows an initial burst but no recent maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release-history evidence of prolonged inactivity.
Composer is used as the build tool, but no security scanning tooling is reported. For this small package, the missing scanning is a modest transparency gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sbwerewolf/json-serialize-trait Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.