The source repository has had no commits or active maintainers for over 12 years, and the package has not released in that time. Its MIT license, readable documentation, and exact-version release notes provide transparency but do not offset the abandonment risk.
28%
Total Score
25
64
75
The package has made 5 releases, but none in the last 12 months; its latest release was over 12 years ago. This strongly increases abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's long release gap and indicating no current maintenance capacity.
There are no open issues or pull requests and no recent issue or pull-request activity. While this avoids an unresolved backlog, it also offers no evidence of an active user or maintainer community.
The repository has 1 star, 0 forks, and 2 watchers, providing little evidence of a broad support community. Popularity is supporting evidence rather than the primary concern.
Composer is used as a build tool, but no security scanning tooling is present. This is a hygiene gap, though the package's much older maintenance state is the more significant concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zendframework Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.