Regular releases, a clear README, and repository tests support dependable maintenance. The small project has strong automation and no unsafe workflow patterns, though its active work remains concentrated in one contributor.
82%
Total Score
80
100
100
75
Only one registry publishing account is listed, which limits publishing redundancy; the matching repository owner and active release history provide some context but do not remove the concentration risk.
One contributor made all four commits in the last three months, giving the project a single-person bus factor and a meaningful continuity risk.
No security policy is present in the repository, leaving vulnerability reporting and response expectations less transparent.
All workflows declare permissions, with four read-only workflows; four use top-level write permissions, which is a manageable but broader-than-minimal automation privilege.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.1.2 || ^2.0.2 | — | — |
psr/http-message Version ^1.0.1 || ^2.0 | — | — |
laminas/laminas-servicemanager Version ^4.5.1 | — | — |
laminas/laminas-permissions-acl Version ^2.18.0 | — | — |
mimmi20/mezzio-generic-authorization Version ^5.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.