The package is stable, licensed, documented, tested in its source repository, and backed by an organization. Maintenance has slowed materially, while workflow dependencies are not pinned and repository security scanning is absent.
68%
Total Score
75
93
100
The latest registry release was about 2 years and 8 months ago, with no releases in the last 12 months. This is meaningful maintenance caution despite a history of nine releases since 2020.
The repository recorded zero commits and zero active maintainers in the last 3 months, which weakens evidence of ongoing maintenance. The repository is still available and not archived, but that does not replace recent activity.
Both analyzed workflows use unpinned action references, so their build dependencies can change without a version update. There are no dangerous triggers, untrusted checkouts, script injections, or audit findings, which limits this to a hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-cache Version ^3.3 | — | — |
laminas/laminas-session Version ^2.12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.