Healthy and suitable to use, with a thin recent contributor base as the main caveat. It has current stable releases, active organizational backing, matching source code, and strong repository hygiene, though only one maintainer made a commit in the last three months.
78%
Total Score
75
100
94
90
All recent commits came from one contributor, creating concentration risk; the organization-owned repository provides some ability to hand maintenance off, but no second recent contributor is shown.
Only one commit was made by one active maintainer in the last three months, indicating limited recent development activity despite the recent release and merged pull request.
Composer build tooling is present, but no security-scanning tool was detected, leaving a security-hygiene gap without making the package unfit to use.
Neither workflow declares top-level token permissions, so least-privilege intent is not explicit; however, no workflow is shown requesting top-level write access.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mezzio/mezzio Version ^3.13.0 | — | — |
symfony/process Version ^6.0.11 || ^8.0.0 | — | — |
laminas/laminas-cli Version ^1.7.0 | — | — |
mezzio/mezzio-router Version ^3.9.0 || ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.