Package Health

laminas/laminas-diactoros

Healthy and suitable to depend on, with strong project backing, a long release history, and an active repository. Recent work is sparse and concentrated in one contributor, so maintenance continuity deserves monitoring.

Latest 3.8.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Are you affected? Scan for Free

Health Score Breakdown

Release historycaution

The package has existed since 2019 with 148 releases, but only two releases occurred in the last 12 months, indicating a mature project with a currently modest release cadence.

Repo bus factorcaution

All two recent commits came from one contributor. Organization backing reduces the risk compared with an individual-owned project, but no second recently active contributor is shown.

Repo commit activitycaution

Only two commits were made in the last three months by one active maintainer, which is thin recent maintenance activity and lowers confidence in continuity.

Repo toolingcaution

The repository uses Composer build tooling, but no security scanning tools were detected, leaving a security-process gap that is partly offset by the separate security policy and clean workflow-risk signals.

Token permissionscaution

All three workflows lack top-level permissions declarations. No workflow requests top-level write access, but explicit least-privilege declarations would provide stronger CI transparency.

Vulnerabilities

TitleVersionsSeverity
CVE-2023-29530
laminas/laminas-diactoros is vulnerable to Improper Input Validation in versions 0.0.0 - 2.18.1, 2.19.0 - 2.19.0, 2.20.0 - 2.20.0, 2.21.0 - 2.21.0, 2.22.0 - 2.22.0, 2.23.0 - 2.23.0, 2.24.0 - 2.24.2 and 2.25.0 - 2.25.2.
0.0.0 - 2.18.12.19.0 - 2.19.02.20.0 - 2.20.0 +5 more
High
CVE-2022-31109
laminas/laminas-diactoros is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.11.1.
0.0.0 - 2.11.1
Medium

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/http-factory
Version ^1.1
psr/http-message
Version ^1.1 || ^2.0

Weekly Downloads

Info

Last Published
11 months ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform