Package Health

contenir/contenir-workflow-mezzio

Database-driven workflow system for Mezzio that generates routes and navigation from hierarchical page structures

Latest v2.1.0PackagistPackagist

64%

Total Score

caution

A new release has no established maintenance record, while CI leaves its only action unpinned and inherits secrets.

Health Score Breakdown

Release historycaution

The package is only 0 days old, with 3 releases in roughly 3 hours, so there is not yet enough history to demonstrate durable maintenance. The rapid initial release activity is mildly reassuring but does not offset the lack of a longer record.

Repo commit activitycaution

There were 0 commits and 0 active maintainers in the last 3 months. Because this release and repository are newly observed and 4 pull requests were merged in the last month, this is a maintenance-confidence concern rather than evidence of abandonment.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool was detected. The missing scanner is a modest repository hygiene gap, not a standalone dependency risk.

Security policycaution

The repository has no security policy. This weakens vulnerability-reporting transparency, although it does not by itself show that the package is unsafe to depend on.

Workflow auditcaution

All 1 workflow was analyzed with no untrusted checkout or script-injection findings, but its only action is unpinned and the high-confidence medium-severity audit found secrets inherited by a reusable workflow. These are concrete CI supply-chain and credential-scope hygiene concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Contenir

Direct Dependencies

DependencyLast ReleaseScore
mezzio/mezzio
Version ^3.18
—
—
psr/container
Version ^1.1 || ^2.0
—
—
psr/http-message
Version ^1.1 || ^2.0
—
—
laminas/laminas-cache
Version ^3.12
—
—
psr/http-server-handler
Version ^1.0.2
—
—

Weekly Downloads

Info

Last Published
2 days ago
Created
2 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform