The package is licensed, documented, tested in its repository, and backed by an organization. Its workflows have no flagged audit findings, but all action references are unpinned, adding avoidable build risk.
68%
Total Score
75
88
100
The package has 79 releases over about 6 years, but only 1 release in the last 12 months, indicating a notably slower current cadence.
The repository recorded 0 commits and 0 active maintainers during the last 3 months, which is a meaningful maintenance concern despite the recent release.
Composer is used for the build, which fits the PHP package, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
All 4 workflows were analyzed successfully with no audit findings or untrusted checkout and script-injection paths. However, all 10 analyzed action references are unpinned, creating avoidable build reproducibility and update risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-stdlib Version ^3.6.0 | — | — |
laminas/laminas-validator Version ^2.15.1 | — | — |
laminas/laminas-servicemanager Version ^3.22 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.