The package is clearly documented, licensed, and backed by an organization with repository tests and release notes. Unpinned workflow actions and no recent commits or registry releases reduce confidence in ongoing maintenance.
65%
Total Score
67
50
88
100
The package declares 12 runtime dependencies, including several Laminas components. This is a substantial dependency surface, but it is coherent with a framework module and is not by itself evidence of poor health.
There have been 33 releases since December 2019, but none in the last 12 months and the latest registry release was July 2023, which is a meaningful maintenance concern.
There were zero commits and zero active maintainers in the last three months, a concrete sign of currently quiet development.
The repository has 11 open issues and 2 open pull requests, but no issues or pull requests were opened or merged in the last month, offering little evidence of current issue resolution.
Composer is used for builds, but no security-scanning tool was detected. This is a modest transparency and hygiene gap rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-mvc Version ^2.7.15 || ^3.0.2 | — | — |
laminas/laminas-http Version ^2.5.4 | — | — |
laminas/laminas-json Version ^2.6.1 || ^3.0 | — | — |
laminas/laminas-view Version ^2.8.1 | — | — |
laminas/laminas-filter Version ^2.7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.