The adapter is documented, licensed, tested in its repository, and backed by an organization. Use the renamed replacement package instead, because this package is explicitly abandoned and its workflow has avoidable credential and pinning weaknesses.
42%
Total Score
75
100
72
75
Packagist marks the entire package as abandoned and identifies contenir/contenir-maintenance-mezzio as the replacement. This directly makes the assessed package a poor dependency choice even though the replacement is closely related.
Four releases appeared within about 18 hours, so the package has too little history to establish long-term maintenance reliability. The recent activity is evidence of current work but not maturity.
There were no commits or active maintainers in the prior three months. Because the package is only hours old and the repository was recently updated, this is weak evidence of abandonment but still leaves long-term maintenance unproven.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this provides no additional adoption or community-depth signal for a very new package.
Composer build tooling is present, but no security scanning tool was detected. For a small PHP adapter this is a hygiene gap rather than a decisive dependency risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.1 || ^2.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
contenir/contenir-config Version ^2.1 | — | — |
laminas/laminas-diactoros Version ^3.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.