The repository has no security policy, and its very limited visible community footprint offers little review capacity. Documentation, licensing, and a matching source repository are present. Treat this as legacy code rather than a new dependency.
39%
Total Score
50
100
71
75
The latest release was about 7 years ago, with no releases in the last 12 months. That long release gap is strong evidence of abandonment risk, despite 17 releases over the project's lifetime.
The repository recorded no commits or active maintainers in the last 3 months, reinforcing that maintenance has stopped rather than merely slowed.
The repository has zero stars and forks and only one watcher, providing little evidence of external review or community support. Popularity is supporting evidence rather than a verdict on its own.
No repository security policy was found. This is a transparency and vulnerability-reporting gap, although it is less significant than the package's long-term inactivity.
The registry reports a non-stable major-version profile and lists 0.8.0 as the latest version despite this assessment targeting 1.6.0. That inconsistency reduces confidence and makes version expectations less clear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version 2.* | — | — |
zendframework/zend-http Version 2.* | — | — |
zendframework/zend-config Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.