Clear documentation, licensing, and repository tests support adoption, with organization backing adding continuity. The package is still very new, and workflow credential handling plus missing security tooling warrant caution.
62%
Total Score
75
86
67
This package was first released today and has 10 releases in the same day, so there is not yet a meaningful track record of long-term maintenance or release stability.
The repository reports zero commits and zero active maintainers in the last three months. Recent release and pull-request activity provides some counterevidence, but the measured commit history still leaves maintenance capacity uncertain.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, which makes vulnerability reporting and response expectations less clear for a package handling form submissions and integrations.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but it has one unpinned action and a high-confidence medium-severity secrets-inherit finding.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
psr/container Version ^1.1 || ^2.0 | — | — |
laminas/laminas-db Version ^2.17 | — | — |
laminas/laminas-mvc Version ^3.8 | — | — |
laminas/laminas-form Version ^3.20 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.