The focused package includes tests, a README, and release notes, with an organization-backed repository. Its workflows have no audit findings, but both action references are unpinned.
70%
Total Score
75
88
100
The package has five releases since November 2021, but none in the last 12 months and a roughly 11-month median interval, indicating slow maintenance rather than abandonment by itself.
There were no commits and no active maintainers in the last three months, which reinforces the slow-maintenance concern, though the package had a release in January 2025.
Composer build tooling is present, but no security scanning tool was detected; the repository's security policy provides some transparency but does not replace automated scanning.
Both workflows were analyzed with no audit findings and no broad top-level write permissions, but both of the two action references are unpinned, leaving avoidable build-reproducibility risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.10 | — | — |
laminas/laminas-cache Version ^3.0 | — | — |
laminas/laminas-stdlib Version ^3.6 | — | — |
laminas/laminas-servicemanager Version ^3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.