Documentation is minimal, and the source offers no security policy or security scanning. The package is not archived and declares a BSD-3-Clause license, but its single maintainer and repository mismatch reduce confidence in long-term support.
32%
Total Score
50
58
75
The package has had only two releases, both in February 2017, with no releases in roughly nine years. This is strong evidence of abandonment risk for a library dependency.
One registry publishing account provides a thin support base. The repository is user-owned rather than organization-backed, so there is no provided evidence of broader maintenance capacity.
The artifact includes a README, but it is only 17 characters long and provides little integration guidance. The absence of tests and a changelog is normal for published artifacts and is not treated as a gap.
The repository name does not match the package name and its README does not mention the package, making it unclear that the linked source belongs to this release.
The repository is not archived, which is a small compensating signal, but it was last pushed in February 2017 and therefore does not demonstrate current maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-mvc Version ^3.0.4 | — | — |
zendframework/zend-i18n Version ^2.7 | — | — |
zendframework/zend-crypt Version ^3.2 | — | — |
gedmo/doctrine-extensions Version ^2.4.24 | — | — |
zendframework/zend-session Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.