Usable with caveats: it has a long release history, clear licensing, a maintained organizational home, and a documented 3.9.0 release. Recent repository activity is absent, and the project lacks security-policy and explicit workflow permission settings.
68%
Total Score
50
50
89
75
The repository recorded zero commits and zero active maintainers over the last three months. This is the strongest concern because it suggests current maintenance may have stalled despite the recent release history.
The package has 19 runtime dependencies, mostly the Laminas components expected for an authentication module; the dependency surface is meaningful but coherent with its stated role.
The project has existed for about 13 years with 35 releases and one release in the last 12 months, showing substantial history but a relatively slow recent cadence.
There are 15 open issues and 11 open pull requests, but none were opened, closed, or merged during the last month, indicating unresolved maintenance backlog.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning coverage is a maintenance and transparency gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-db Version ^2.16 | — | — |
laminas/laminas-mvc Version ^3.4 | — | — |
laminas/laminas-form Version ^3.5 | — | — |
laminas/laminas-http Version ^2.17 | — | — |
laminas/laminas-i18n Version ^2.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.