The package includes tests and a repository that clearly matches its name, but all three workflow actions are unpinned. The registry marks the package deprecated, and its repository is archived with no release activity for over six years.
12%
Total Score
50
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on the package.
The package has had no release in over six years, with zero releases in the last 12 months. That strongly indicates abandonment for a library dependency.
The linked repository is archived and was last pushed nearly five years ago, indicating the project is no longer maintained. This outweighs its organization backing and matching repository.
The workflow audit found no unsafe triggers or audit findings, but all 3 of 3 action references are unpinned. This is a supply-chain hygiene gap, though not severe enough to determine the verdict alone.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpoffice/phpword Version ^0.17 | — | — |
laminas/laminas-mvc Version ^3.1 | — | — |
laminas/laminas-mvc-form Version ^1.0.0 | — | — |
jield-webdev/bjy-authorize Version ^1.4.0 | — | — |
laminas/laminas-navigation Version ^2.9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.