Tests, a readable README, and no install-time scripts help adoption. The code and releases have been untouched since 2013, and the release has no license, so pinning it creates substantial maintenance and legal risk.
35%
Total Score
0
67
83
The latest release was on November 10, 2013, with no releases in the last 12 months. This is strong evidence of abandonment for a package intended as an application dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history and leaving no evidence of current maintenance.
Neither the package metadata nor the checked repository contains a license declaration or license file. That creates a genuine legal and adoption risk for downstream projects.
Composer is used for builds, but no security scanning tools are present. This is a secondary hygiene gap alongside the much more significant age and maintenance concerns.
The repository has no security policy. For an authentication module, that reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zf-commons/zfc-base Version 0.* | — | — |
zf-commons/zfc-user Version 0.* | — | — |
hybridauth/hybridauth Version dev-master | — | — |
zendframework/zendframework Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.