The package is licensed, tested, and documents this release with GitHub notes. Recent work is concentrated in one contributor, and all three workflow actions are unpinned, while organization backing and a non-archived repository reduce abandonment concerns.
78%
Total Score
83
88
75
The package has existed for about 3 years and 4 months with five releases, but only one release in the last 12 months and a median interval of about 200 days indicate a measured rather than rapid cadence.
One contributor made all seven commits in the last 3 months, creating a meaningful continuity risk; organization ownership provides some ability to hand maintenance off.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest security-process gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less transparent.
The single workflow was fully analyzed with no injection or high-severity findings, but all three action references are unpinned, weakening build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
dvsa/mot-logger Version ^3.3 | — | — |
laminas/laminas-mvc Version ^3.3.0 | — | — |
laminas/laminas-json Version ^3.3 | — | — |
laminas/laminas-router Version ^3.4 | — | — |
laminas/laminas-inputfilter Version ^2.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.