Unfit to use for a new dependency: the package is deprecated and its source repository is archived. It has solid documentation, tests, licensing, and a correctly linked organizational repository, but those strengths do not offset the lack of releases since July 2022 and discontinued project status.
18%
Total Score
50
50
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because the release is explicitly withdrawn from ongoing support.
The package has 12 releases over more than 10 years, but none in the last 12 months and the latest release was in July 2022. The long release gap supports the evidence of abandonment.
The repository recorded no commits and no active maintainers in the last three months. This confirms that current maintenance capacity is absent rather than merely inferred from registry metadata.
The linked repository is archived, indicating the project is no longer maintained even though it was last pushed in March 2024. Archived status materially limits the likelihood of fixes or compatibility updates.
The repository uses Composer build tooling, but it has no security-scanning tools. The missing scanning is a transparency gap, though it is secondary to the package's explicit abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jms/metadata Version ~2.6 | — | — |
jms/serializer Version ~3.17 | — | — |
symfony/validator Version ~5.0 | — | — |
doctrine/annotations Version ~1.13 | — | — |
symfony/security-core Version ~5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.