Clear documentation, source tests, and a matching repository make the package easy to inspect. Its small dependency footprint and lack of install scripts reduce operational complexity. Use mezzio/mezzio-csrf instead.
12%
Total Score
50
100
56
75
Packagist marks the entire package as abandoned and names mezzio/mezzio-csrf as its replacement. Package-wide deprecation is a severe adoption risk.
The latest release was published on June 24, 2019, and there have been no releases in the last 12 months. This strongly indicates the package is stale.
The repository had zero commits and zero active maintainers in the last three months. This provides no evidence of ongoing maintenance.
The linked repository is archived, with its last push on January 29, 2020. Archived source indicates the project is no longer maintained.
The repository uses Composer, but no security scanning tools were detected. This is a secondary hygiene gap, outweighed by the stronger maintenance evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
zendframework/zend-expressive-session Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.