laminas/laminas-tag 2.14.0 appears suitable for dependency use: it is a stable, non-deprecated package with nearly seven years of release history, a current release, an active non-archived organization-owned repository, documented licensing, repository tests, security policy, and no install-time lifecycle scripts or dangerous workflow patterns. The main concerns are limited recent commit activity, low repository popularity, absent repository security-scanning tooling, and workflows that do not declare top-level token permissions; these reduce transparency and maintenance confidence but do not indicate abandonment, especially given the recent release and ongoing pull-request activity.
82%
Total Score
83
100
89
90
No commits and no active maintainers were recorded in the last three months, which is a meaningful maintenance concern; the recent release and pull-request activity provide partial compensation but do not remove the signal.
The repository has only 5 stars and 10 forks, indicating limited adoption evidence; popularity is supporting evidence rather than a health verdict, so this is a modest concern.
Composer build tooling is present, but no security-scanning tools were detected, leaving a security-hygiene gap in the repository.
None of the three workflows declares top-level token permissions, so least-privilege intent is not explicit and workflow credentials may be broader than necessary.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-stdlib Version ^3.6 | — | — |
laminas/laminas-escaper Version ^2.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.