The package includes tests and a matching organization-backed project with dependency scanning. Its proprietary licensing and three unpinned workflow actions reduce transparency and build reproducibility.
12%
Total Score
50
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning that developers should not start new dependencies on this package.
The package has seven releases since 2014, but none in the last 12 months; its latest release was in January 2020. This strongly indicates prolonged release inactivity.
The repository recorded no commits and no active maintainers in the last three months. This confirms the lack of current maintenance rather than merely a slow release schedule.
The linked repository is archived, and its last push was in October 2021. Archived source indicates the project is no longer maintained for ongoing dependency use.
The manifest declares a proprietary license, while no license file was detected in the package or repository. That leaves the legal terms and redistribution rights unclear for an open-source dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-mvc Version ^3.1 | — | — |
laminas/laminas-mvc-form Version ^1.0.0 | — | — |
jield-webdev/bjy-authorize Version ^1.4.0 | — | — |
laminas/laminas-navigation Version ^2.9.0 | — | — |
laminas/laminas-mvc-console Version ^1.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.