Security scanning is absent and all three workflow actions are unpinned, increasing maintenance and build-integrity concerns. Organization backing, a clear release note, tests in the repository, and an active repository reduce abandonment risk.
68%
Total Score
67
88
100
The package has 9 releases over roughly 6 years, with no releases in the last 12 months and a median interval of about 247 days, indicating a slow cadence rather than active maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, which is a concrete sign of currently limited development activity.
There were no new or closed issues or pull requests in the last month, although 6 open pull requests show that some work remains visible.
Composer is used for builds, but no security-scanning tools are configured, leaving a meaningful transparency and maintenance gap for dependency health.
All 3 analyzed action references are unpinned, which weakens build reproducibility; however, the audit found no untrusted checkouts, script injection, or other flagged workflow findings, and only one workflow has top-level write permissions.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.9 | — | — |
laminas/laminas-mvc Version ^3.2 | — | — |
psr/http-server-handler Version ^1.0.2 | — | — |
laminas/laminas-psr7bridge Version ^1.10 | — | — |
psr/http-server-middleware Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.