The project has regular releases, current repository activity, tests, and a clear license. Workflow actions are all unpinned and no security policy is published, so keep the dependency under review.
72%
Total Score
75
100
100
50
One contributor made all 11 recent commits, leaving no demonstrated second active contributor; organization ownership partly helps but does not remove the continuity risk.
Eleven commits were made in the last three months, showing active maintenance, although all activity is concentrated in one maintainer.
The repository has no published security policy, which leaves reporting and response expectations unclear for a library used in applications.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all 9 action references are unpinned, reducing build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jms/serializer Version ^2.1 || ^3.5 | — | — |
doctrine/annotations Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.