It has a stable major release, a clear README, repository tests, and strong security scanning. All 18 workflow actions are unpinned, and zero commits were made in the last three months, limiting confidence in future fixes.
12%
Total Score
50
75
75
Packagist marks the entire package as abandoned, with no replacement provided; this is a direct warning against taking a new dependency on it.
The linked source repository is archived, which sharply raises abandonment and future-maintenance risk even though it was last pushed in November 2025.
The repository recorded zero commits and zero active maintainers in the last three months, providing no recent evidence of ongoing development.
All 18 analyzed action references are unpinned, creating avoidable workflow supply-chain exposure. Two workflows grant top-level write permissions, while the high-confidence template-injection finding remains a hygiene concern because no dangerous trigger or untrusted checkout was reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-http Version ^2.22.0 | — | — |
laminas/laminas-servicemanager Version ^4.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.