Package Health

laminas/laminas-i18n-resources

Usable with caveats: this is a licensed, stable release from an organization-backed repository with tests, release notes, and no deprecation or install scripts. Maintenance has been quiet recently, with no commits or issue activity in three months, and workflow permissions are not consistently restricted.

Latest 2.13.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historycaution

The package has existed for about 6 years 9 months with 73 releases, but only one release was published in the last 12 months. That slower cadence is a maintenance caution for a package whose contents may reasonably change infrequently.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months. The recent repository push and current release provide some compensation, but the lack of ongoing commit activity still lowers confidence in rapid maintenance response.

Repo issue activitycaution

No issues were opened or closed and no pull requests were merged in the last month, indicating limited recent development activity. This is a caution rather than a severe risk because the package is a small, stable resource collection.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool was detected. The absence of scanning reduces transparency around automated security checks, though it is partly offset by the repository's security policy and straightforward package structure.

Token permissionscaution

Two of three workflows lack top-level token permissions, and one workflow requests write access. This is a workflow-hardening gap, although the dangerous-workflow analysis found no untrusted checkout, script injection, or pull-request-target risks.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
11 months ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform