The MIT license, README, repository tests, and security scanning provide useful transparency. The registry marks the package abandoned and its repository is archived, so choose an actively maintained replacement.
15%
Total Score
50
71
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption and maintenance risk even though the deprecation does not target only this release.
The linked repository is archived, which strongly indicates that active maintenance has ended. Its last push was on November 4, 2025, so future fixes and releases are unlikely.
The repository had zero commits and zero active maintainers in the last three months. Although release history shows two releases in the last 12 months, the current source activity still indicates weak ongoing maintenance.
The repository has no security policy. This is a modest transparency gap, particularly for a package with no active repository maintenance.
All 18 analyzed action references are unpinned, and two workflows grant top-level write permissions; these are workflow hygiene concerns. The high-confidence template-injection finding is also notable, though no untrusted checkout or script-injection trigger was reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-form Version ^3.22.0 | — | — |
laminas/laminas-view Version ^2.43.0 | — | — |
laminas/laminas-inputfilter Version ^2.34.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.