The package is clearly identified, licensed, documented, and backed by an organization. Its small footprint and clean workflow audit help, but no commits were recorded in the last three months, so ongoing maintenance is less certain.
68%
Total Score
67
100
94
100
No commits and no active maintainers were recorded during the last three months. Despite the recent repository push and current release, this weakens confidence in continued maintenance.
One issue was closed in the last month, but there were no newly opened issues or merged pull requests. This shows limited recent project activity rather than complete abandonment.
Composer is used for builds, but no security scanning tools were detected. The missing scanning is a hygiene gap, not evidence that the release is unsafe by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 || ^2.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0.1 || ^2.0.0 | — | — |
mezzio/mezzio-authentication Version ^1.10 | — | — |
laminas/laminas-authentication Version ^2.11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.