The package has a clear README, an MIT declaration, repository tests, and a matching source repository. Its small project offers limited maintenance capacity and lacks a security policy or scanning, so pinning this version carries some risk.
60%
Total Score
50
100
79
75
The latest release was about 2 years and 8 months ago, and there were no releases in the last 12 months. Four releases show some history, but the long gap raises maintenance risk.
There were zero commits and zero active maintainers during the last 3 months. Combined with the old last push, this is meaningful evidence of inactivity.
Composer is used as the build tool, but no security scanning tools were detected. This is a transparency and hygiene gap, not evidence that the package is unsafe.
The repository has no security policy. For a small application module this is a modest transparency gap, while the matching repository and available tests provide some compensating context.
Version 0.3.0 is not a stable major release, although it is not marked as a prerelease and recent releases were not predominantly prereleases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-mvc Version ^3.1 | — | — |
laminas/laminas-eventmanager Version ^3.2 | — | — |
laminas/laminas-servicemanager Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.