Usable with caveats: the package is licensed, clearly backed by its matching repository, and the stable release includes release notes. However, it has had no registry release for nearly four years and no commits or active maintainers in the last three months, so maintenance may be limited.
62%
Total Score
50
100
88
67
The registry namespace and repository owner match, but the owner is an individual rather than an organization. This is consistent ownership evidence, though it indicates a relatively small backing structure.
Only three releases have been published since April 2020, with no release in nearly four years and a median interval of about 14 months. This is a meaningful sign of limited ongoing release maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the long release gap, this raises a material risk of slow fixes and abandonment.
There are ten open pull requests but no issues or pull requests were merged in the last month, suggesting limited recent project throughput.
Composer is used for the build, but no security scanning tools were detected. The missing scanner is a transparency gap, though it does not by itself make the package unfit to use.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-mvc Version ^3.1 | — | — |
laminas/laminas-view Version ^2.11 | — | — |
laminas/laminas-stdlib Version ^3.2 | — | — |
laminas/laminas-eventmanager Version ^3.2 | — | — |
laminas/laminas-modulemanager Version ^2.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.