Usable with caveats: this is a mature, well-documented MIT package with a matching repository, tests, and a recent release. However, the repository shows no commits or issue activity in the last three months, and it lacks a security policy and explicit workflow permissions.
72%
Total Score
67
100
94
67
The repository recorded zero commits and zero active maintainers in the last three months. The recent release provides some compensating evidence, but the current absence of development activity is a meaningful maintenance concern.
There were no new or closed issues or pull requests in the last month, despite 31 open issues. This may indicate a quiet project and adds to the maintenance uncertainty alongside the lack of recent commits.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and process gap, though it is not severe enough to outweigh the recent release, tests, and established repository.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability reporting guidance unclear for consumers.
Both analyzed workflows lack top-level token permissions declarations. No workflow has top-level write access, which limits the concern, but explicit least-privilege settings would improve build hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jms/metadata Version ^2.0 | — | — |
jms/serializer Version ^3.18.2 | — | — |
symfony/expression-language Version ^5.4 || ^6.4 || ^7.3 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.