Documentation, tests, changelog, licensing, and package ownership are clear. The project has no security scanning or published security policy, so long-term maintenance assurance is limited.
67%
Total Score
50
50
81
67
Seven runtime dependencies create a meaningful dependency surface for a serialization library, though the profile is explicit and not unusually large for the package's functionality.
The registry namespace and repository owner match, and the owner is an individual account. This is consistent ownership, but it indicates a smaller backing structure than an organization-owned project.
There were no commits and no active maintainers in the last three months. Recent registry releases partly offset this, but the lack of source activity weakens confidence in ongoing maintenance.
The repository has zero stars, forks, and watchers. Popularity is not decisive, but this provides little external evidence of review or community support.
Composer build tooling is present, but no security scanning tools were detected. The build setup is established while automated security oversight is limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^3.3|^4.0|^5.0|^6.0 | — | — |
tebru/php-type Version ^0.1.7 | — | — |
psr/simple-cache Version ^3.0 | — | — |
phpdocumentor/reflection-docblock Version ^3.2.3|^4.0.1|^5 | — | — |
taquillacom/doctrine-annotation-reader Version ^0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.