The repository has no security policy, and all eight workflow actions are unpinned. Licensing, repository tests, and release notes are present, but they do not offset the lack of recent maintenance.
42%
Total Score
0
63
75
Only two releases were published, both in February 2023, with no release in over three years. This leaves substantial uncertainty about ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with a project that is no longer actively maintained.
The repository has zero stars, forks, and watchers, offering no supporting evidence of community adoption or review. Popularity is only supporting evidence, so this reinforces rather than determines the maintenance concern.
The repository has no security policy, reducing transparency about how vulnerabilities are reported and handled. Its otherwise visible source repository provides some context but does not replace this process.
All eight analyzed action references are unpinned, weakening build reproducibility and allowing referenced action code to change. The audit found no dangerous triggers, untrusted checkouts, script injection, or other reported findings.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-http Version ^2.5.4 | — | — |
laminas/laminas-stdlib Version ^2.7.8 || ^3.0.1 | — | — |
oldcodefork/laminas-mvc Version ^1.0 | — | — |
laminas/laminas-eventmanager Version ^3.2 | — | — |
laminas/laminas-authentication Version ^2.5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.