Package Health

contenir/contenir-workflow

Database-driven workflow system for Mezzio that generates routes and navigation from hierarchical page structures

Latest v2.1.0PackagistPackagist

22%

Total Score

critical

This release is abandoned on Packagist; use contenir/contenir-workflow-mezzio instead.

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the package abandoned at package scope and names contenir/contenir-workflow-mezzio as its replacement. That directly makes this release unsuitable as a new dependency despite the active replacement repository.

Repo commit activitycaution

The repository shows zero commits and zero active maintainers in the last 3 months, although it was pushed recently and had four merged pull requests in the last month. The recent repository transition makes this mixed rather than conclusive abandonment evidence.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not a standalone reason to reject the package.

Security policycaution

The linked repository has no security policy. That weakens vulnerability-reporting transparency, though it is secondary to the explicit registry replacement.

Workflow auditcaution

The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but its only action use is unpinned and the audit found a high-confidence medium-severity secrets-inherit issue. These are avoidable workflow hygiene and credential-scope concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Contenir

Direct Dependencies

DependencyLast ReleaseScore
mezzio/mezzio
Version ^3.18
—
—
psr/container
Version ^1.1 || ^2.0
—
—
psr/http-message
Version ^1.1 || ^2.0
—
—
laminas/laminas-cache
Version ^3.12
—
—
psr/http-server-handler
Version ^1.0.2
—
—

Weekly Downloads

Info

Last Published
2 days ago
Created
2 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform