The codebase is small and documented, with repository tests and a stable release. Its maintenance record is the main concern, with no recent commits or releases for about five years; the repository also has no security policy or scanning tools.
58%
Total Score
50
100
88
83
There were no commits and no active maintainers in the last three months, consistent with the last repository push being about five years ago. This materially lowers confidence in ongoing maintenance.
The latest release was published about five years ago, and there were no releases in the last 12 months. That long gap raises abandonment risk despite the package having nine releases since 2020.
There are no open issues or pull requests, and no recent issue or pull-request activity. This is consistent with a quiet project but does not compensate for the absence of recent commits.
Composer build tooling is present, but no security scanning tools were detected. For a small library this is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it is less significant than the demonstrated maintenance inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-log Version ^2.13 | — | — |
laminas/laminas-http Version ^2.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.