MIT licensing and organization backing provide useful transparency, while install-time Composer hooks add operational complexity. The project also has no security policy, leaving maintenance expectations unclear.
38%
Total Score
50
75
50
The package has had only two releases, both in September 2017, with no releases in roughly nine years. That is strong evidence of abandonment for a dependency.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long release gap and leaving current maintenance un demonstrated.
The package runs pre-install, post-install, pre-update, and post-update Composer scripts, increasing install and update complexity even though no other supplied signal shows those scripts are harmful.
The linked repository has no security policy, reducing transparency about vulnerability reporting and response expectations. This adds a maintenance concern but is less serious than the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zendframework Version 2.4.* | — | — |
evandotpro/edp-module-layouts Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.