The package is clearly licensed, has tests, and keeps runtime dependencies minimal. Its small audience, absent security policy, and lack of recent release or issue activity leave maintenance uncertainty.
58%
Total Score
25
100
79
50
The latest release was about seven years ago, despite 20 releases overall and a previously regular cadence. No releases appeared in the last 12 months, which materially raises abandonment and compatibility risk.
The repository had no commits and no active maintainers in the last three months. The repository was pushed about three years ago, so maintenance appears to have largely stopped.
There were three open issues and three open pull requests, with no issues or pull requests opened or merged in the last month. This suggests limited recent project responsiveness.
Composer build tooling is present, but no security-scanning tools were detected. That weakens evidence that security-sensitive changes receive automated checking.
The repository has no security policy. For a package focused on safely handling serialized input, this is a meaningful transparency and vulnerability-reporting gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.