Database-driven workflow system for Mezzio that generates routes and navigation from hierarchical page structures
64%
Total Score
caution
A new release has no established maintenance record, while CI leaves its only action unpinned and inherits secrets.
The package is only 0 days old, with 3 releases in roughly 3 hours, so there is not yet enough history to demonstrate durable maintenance. The rapid initial release activity is mildly reassuring but does not offset the lack of a longer record.
There were 0 commits and 0 active maintainers in the last 3 months. Because this release and repository are newly observed and 4 pull requests were merged in the last month, this is a maintenance-confidence concern rather than evidence of abandonment.
Composer build tooling is present, but no security scanning tool was detected. The missing scanner is a modest repository hygiene gap, not a standalone dependency risk.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it does not by itself show that the package is unsafe to depend on.
All 1 workflow was analyzed with no untrusted checkout or script-injection findings, but its only action is unpinned and the high-confidence medium-severity audit found secrets inherited by a reusable workflow. These are concrete CI supply-chain and credential-scope hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mezzio/mezzio Version ^3.18 | — | — |
psr/container Version ^1.1 || ^2.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
laminas/laminas-cache Version ^3.12 | — | — |
psr/http-server-handler Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.