Package Health

laminas/laminas-mvc-middleware

Security scanning is absent and all three workflow actions are unpinned, increasing maintenance and build-integrity concerns. Organization backing, a clear release note, tests in the repository, and an active repository reduce abandonment risk.

Latest 2.5.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historycaution

The package has 9 releases over roughly 6 years, with no releases in the last 12 months and a median interval of about 247 days, indicating a slow cadence rather than active maintenance.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months, which is a concrete sign of currently limited development activity.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, although 6 open pull requests show that some work remains visible.

Repo toolingcaution

Composer is used for builds, but no security-scanning tools are configured, leaving a meaningful transparency and maintenance gap for dependency health.

Workflow auditcaution

All 3 analyzed action references are unpinned, which weakens build reproducibility; however, the audit found no untrusted checkouts, script injection, or other flagged workflow findings, and only one workflow has top-level write permissions.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
webmozart/assert
Version ^1.9
laminas/laminas-mvc
Version ^3.2
psr/http-server-handler
Version ^1.0.2
laminas/laminas-psr7bridge
Version ^1.10
psr/http-server-middleware
Version ^1.0.2

Weekly Downloads

Info

Last Published
1 year ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform