The organization-owned repository matches the package and provides release notes, a README, and a license. Unpinned workflow actions and the absence of a security policy weaken operational transparency.
58%
Total Score
67
79
75
The package has had no release in about 3 years and 6 months, with zero releases in the last 12 months. Its six-release history shows an effectively abandoned release cadence.
The repository recorded zero commits and zero active maintainers in the last 3 months, indicating no current maintenance activity. The repository is not archived, but that does not offset the recent inactivity.
There were no new or closed issues or pull requests in the last month, while two pull requests remain open. This provides little evidence of active support or development.
The repository has only 1 star and no forks, so there is limited external adoption or community visibility. Popularity is supporting evidence rather than a verdict, but it offers little compensating confidence here.
No security policy was found in the repository, reducing transparency about vulnerability reporting and response. The package still has a linked, matching repository, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
jms/serializer Version ^3.22 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.