The package has no security policy or automated security scanning, and its install-time scripts add operational risk. Its license, repository tests, and organization-backed source provide useful transparency, but do not offset the age.
22%
Total Score
100
56
50
The package has made no release in about 10 years, with only four releases overall and none in the last 12 months. This is strong evidence of abandonment for a dependency.
The repository is not archived, but it was last pushed on August 26, 2016, matching the stale registry history and providing no evidence of ongoing maintenance.
post-install-cmd and post-update-cmd scripts run during dependency operations, adding execution and maintenance surface beyond ordinary file installation.
The repository has zero stars and forks and only one watcher, offering little supporting evidence of adoption or external scrutiny. Popularity is not decisive, but it reinforces the abandonment concern.
Composer is used for builds, but no security scanning tool was detected, leaving limited evidence of ongoing security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-db Version ^2.8 | — | — |
roave/security-advisories Version dev-master | — | — |
zendframework/zend-hydrator Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.