Unfit to use: the package is marked abandoned and its source repository is archived, with no commits or releases for years. Although it has tests, licensing, and documented release notes, it is not maintained for current dependencies.
15%
Total Score
0
42
75
Packagist marks the entire package as abandoned, with no replacement named. This is a severe adoption risk because the registry itself signals that ongoing maintenance has ended.
The package has 16 releases but none in the last 12 months; its latest release was in September 2013 despite the package being over 13 years old. This indicates prolonged release abandonment.
There were no commits and no active maintainers in the last 3 months, consistent with the archived repository and abandoned registry status.
The linked repository is archived, and its last push was in May 2018. An archived source project is not expected to receive fixes or compatibility updates.
Composer is used for builds, but no security-scanning tooling is reported. This is a secondary hygiene gap, outweighed by the stronger evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-mvc Version ~2.1 | — | — |
zendframework/zend-http Version ~2.1 | — | — |
zendframework/zend-view Version ~2.1 | — | — |
zendframework/zend-cache Version ~2.1 | — | — |
zendframework/zend-eventmanager Version ~2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.