Package Health

contenir/contenir-maintenance-laminas-mvc

It has clear documentation, a matching repository, organization backing, and repository tests. The workflow inherits secrets and uses an unpinned action, while the package is too new to show long-term maintenance.

Latest v2.2.0PackagistPackagist

76%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

All 8 releases were published within the same day and the package is 0 days old, so there is not yet evidence of sustained release maintenance.

Repo commit activitycaution

There were no commits or active maintainers in the prior 3 months, but the package was only released today and the repository shows 5 merged pull requests in the last month; long-term activity remains unproven.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.

Security policycaution

The repository has no published security policy, which reduces transparency for reporting and handling vulnerabilities.

Workflow auditcaution

The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but it has one high-confidence medium-severity secrets-inherit finding and its only action use is unpinned.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/container
Version ^1.1 || ^2.0
—
—
laminas/laminas-mvc
Version ^3.7
—
—
laminas/laminas-http
Version ^2.19
—
—
laminas/laminas-eventmanager
Version ^3.13
—
—
contenir/contenir-maintenance
Version ^2.1
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform