The package includes a substantial README, extensive tests, and matching MIT licensing. A single maintainer, no security policy, and no security scanning leave limited ongoing support evidence.
42%
Total Score
38
50
67
75
The package has had no releases in about six years: its latest release was in August 2020, despite 10 releases early in its history. This is strong evidence of abandonment risk.
The repository has zero commits and zero active maintainers in the last three months. Combined with the last push being about six years ago, this materially raises abandonment risk.
Nine runtime dependencies create a meaningful maintenance surface for this library, including several framework and package-specific dependencies. The signal does not show that any dependency is unmaintained or unsafe, so this is a limited concern.
Only one registry account has publish access. That is not inherently unhealthy for an individual-owned project, but it leaves little publishing redundancy when combined with the lack of recent activity.
The repository is owned by the same individual namespace as the package, so the source-package relationship is transparent. The owner type is an individual, providing less organizational continuity than a backed project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/common Version ^2.0 | — | — |
laminas/laminas-mvc Version 3.1.1 | — | — |
doctrine/annotations Version ^1.10 | — | — |
laminas/laminas-session Version ^2.9 | — | — |
alichry/laminas-accesscontrol Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.