The package is licensed, documented, and its repository clearly matches the published package. Its stable packaging and clean workflow audit cannot compensate for the lack of ongoing maintenance.
12%
Total Score
50
50
88
Packagist marks the entire package as abandoned and names laminas/laminas-cli as its replacement. This is a direct adoption warning and outweighs the package's otherwise healthy metadata.
The package has had no releases in the last 12 months, and its latest release was December 28, 2020. This supports the conclusion that development has stopped rather than merely slowed.
There were zero commits and zero active maintainers in the last three months. This confirms there is no current maintenance capacity.
The source repository is archived, with its last push on February 23, 2021. An archived project is no longer maintained and is a severe dependency risk.
Both workflows were analyzed successfully with no untrusted checkout, script injection, or auditor findings. However, both of the two action references are unpinned, leaving a minor reproducibility and workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-mvc Version ^3.0.3 | — | — |
laminas/laminas-text Version ^2.6 | — | — |
laminas/laminas-view Version ^2.11.3 | — | — |
laminas/laminas-router Version ^3.0 | — | — |
laminas/laminas-stdlib Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.