The package includes tests, a README, and release notes, with no install-time scripts. Its last release and repository activity were in 2022, and the license files conflict; the missing security policy adds transparency risk.
35%
Total Score
33
50
69
83
The latest release was 1,559 days after the package's first release, but there have been no releases in the last 12 months. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the 2022 release history, this indicates a substantial abandonment risk.
The package declares 10 runtime dependencies, including framework, cache, serialization, and CLI components. This is a meaningful dependency surface, though not by itself evidence of poor maintenance.
The artifact contains a license file and the repository also has one, so licensing is documented; however, the manifest declares MIT while the detected file is BSD-3-Clause, creating a material mismatch.
The repository is owned by an individual user rather than an organization. This does not prove poor health, but it provides less visible backing to compensate for the inactive history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/common Version ^3.0 | — | — |
laminas/laminas-cli Version 1.8.x | — | — |
laminas/laminas-mvc Version 3.4.x-dev | — | — |
laminas/laminas-code Version 3.5.1 | — | — |
laminas/laminas-cache Version 3.7.x-dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.