The package is small, documented, MIT-licensed, and does not run install-time scripts. Organization backing, an aligned repository, and a changelog provide useful transparency, but the available maintenance evidence is limited.
58%
Total Score
75
75
75
The package has had no release in over four years, with only three releases overall and none in the last 12 months. This is a meaningful maintenance concern, although the repository was pushed more recently.
There were zero commits and zero active maintainers in the last three months, so current development activity is not demonstrated. The repository is not archived and has a more recent push, which partially offsets the concern.
The repository uses Composer for builds, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
No security policy was found in the linked repository, leaving vulnerability-reporting expectations unclear. The package's clear repository alignment and documentation provide some compensating transparency.
Version 0.2.1 is not a stable-major release, so compatibility expectations are less mature than for a 1.x package. It is not marked as a prerelease, which avoids an additional stability concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
inanepain/inane Version * | — | — |
laminas/laminas-db Version * | — | — |
laminas/laminas-hydrator Version * | — | — |
laminas/laminas-paginator Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.