The project includes tests, release notes, and dependency scanning. Long release gaps and workflow hygiene leave some maintenance and build-integrity uncertainty.
65%
Total Score
83
100
94
75
The package has existed for over 6 years but has only 8 releases, with a median interval of about 13 months and one release in the last 12 months. The recent release shows the project is not abandoned, but maintenance is infrequent.
There were no commits and no active maintainers in the last 3 months. Although a release was published recently, the lack of recent commit activity limits evidence of ongoing maintenance.
No repository security policy was found. This is a transparency gap, though the presence of Dependabot provides some compensating security tooling.
All 15 analyzed action references are unpinned, and the audit found a high-confidence bot-condition issue in a pull_request_target workflow; that workflow also has top-level write permissions. No untrusted checkout or script injection was found, so this is a meaningful hygiene caution rather than a severe dependency verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mezzio/mezzio Version ^3.27 | — | — |
psr/container Version ^2.0 | — | — |
mezzio/mezzio-router Version ^4.2 | — | — |
laminas/laminas-diactoros Version ^3.8 | — | — |
laminas/laminas-stratigility Version ^4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.