It includes tests, a README, release notes, and a matching repository, which support adoption. The repository is not archived, but no recent commit or release activity limits confidence.
52%
Total Score
50
83
67
The package has had no release in over six years, despite four releases during its first few weeks. That is a meaningful maintenance concern, though the stable v1.2.0 status and release notes provide some transparency.
The repository recorded no commits and no active maintainers in the last three months, consistent with a project whose development has stopped. It is not archived, which slightly reduces the abandonment concern but does not restore current maintenance.
The repository has no security policy, leaving vulnerability-reporting expectations unspecified. This is a transparency gap, but the package's tests, license, and otherwise straightforward repository structure provide some compensating evidence.
The single workflow was fully analyzed with no reported findings, unsafe triggers, or script-injection sinks. Its one action is unpinned, a minor reproducibility and update-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^4.3 | — | — |
laminas/laminas-mvc Version ^3.1 | — | — |
laminas/laminas-stdlib Version ^3.2 | — | — |
laminas/laminas-servicemanager Version ^3.4 | — | — |
container-interop/container-interop Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.