The release includes a license, tests, a changelog, and a repository that matches the package. Its 12 runtime dependencies, install scripts, and absent security policy increase the upkeep and review burden.
38%
Total Score
75
50
81
50
The package declares 12 runtime dependencies, including several framework components, creating a relatively broad compatibility and maintenance surface for an old release.
post-install-cmd and post-update-cmd scripts run during dependency operations, adding execution and maintenance surface that consumers must trust and review.
The package has had no release in about 10 years and none in the last 12 months, indicating a strong abandonment concern despite its five-release history.
The repository had zero commits and zero active maintainers in the last three months, consistent with the last push being about 10 years ago and indicating likely abandonment.
The repository has zero stars and forks and only one watcher, providing little community evidence to offset its long inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 | — | — |
zendframework/zend-mvc Version ^3.0 | — | — |
roave/security-advisories Version dev-master | — | — |
zendframework/zend-router Version ^3.0 | — | — |
zendframework/zend-diactoros Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.