The source has had no commits or active maintainers for nearly five years, and the registry has had no release in that time. It remains licensed and documented, but its maintenance risk is too high for a new dependency.
38%
Total Score
0
67
75
The package has had no releases in the last 12 months, and its latest release was nearly five years ago despite 30 historical releases. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap and indicating no current maintenance capacity.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these values provide no external adoption signal to offset the lack of recent activity.
The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, although it is secondary to the much larger maintenance concern.
The release is a stable major version and not a prerelease, which is positive, but the recorded latest version is 3.4.1 while the assessed release is v3.5.0, creating release metadata uncertainty.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-db Version ^2.11 | — | — |
laminas/laminas-mvc Version ^3.0 | — | — |
laminas/laminas-form Version ^3.0 | — | — |
laminas/laminas-http Version ^2.11 | — | — |
laminas/laminas-i18n Version ^2.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.