Builds laminas-mvc routes and laminas-navigation pages from a tree of Contenir resources, one workflow per resource type
68%
Total Score
caution
Stable, licensed, and documented, but no recent commit history and workflow secret inheritance reduce confidence.
Sixteen releases were published on the same day and the package is only 0 days old, showing active initial publishing but providing no long-term release track record.
No commits and no active maintainers were recorded in the last three months. Because the package is newly published and the repository was recently pushed, this is a meaningful but not conclusive maintenance concern.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest gap in repository hygiene.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
The sole workflow has one high-confidence medium-severity secrets-inherit finding and its only action use is unpinned. The workflow has no untrusted checkout or script-injection sink, so these are hygiene concerns rather than severe supply-chain risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.1 || ^2.0 | — | — |
laminas/laminas-mvc Version ^3.8 | — | — |
laminas/laminas-cache Version ^3.12 | — | — |
laminas/laminas-router Version ^3.13 | — | — |
contenir/contenir-metadata Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.