Package Health

codingmatters/zend-expressive-zend-component

Repository tests and MIT licensing provide a useful baseline, but the tiny artifact offers little documentation for consumers. There is no security policy or scanning, and visible project adoption is minimal.

Latest 0.4.0PackagistPackagist

38%

Total Score

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

56

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The latest release was published in March 2017, with no releases in the last 12 months. That long period without updates is strong evidence of abandonment risk.

Package scaffoldingcaution

The published artifact has no README, which is a documentation gap for a library consumers must integrate. The source repository does contain tests, partly offsetting the small artifact's limited scaffolding.

Repo package mentioncaution

The repository name does not match the package name, and no README package mention was available. The linked repository may not clearly belong to this package, which weakens provenance transparency.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of active community support.

Repo toolingcaution

Composer is used for builds, but no security scanning tools were detected. This is a maintenance and transparency gap, though not severe on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
ocramius/proxy-manager
Version ^2.1
—
—
roave/security-advisories
Version dev-master
—
—
zendframework/zend-servicemanager
Version ^3.3
—
—
zendframework/zend-expressive-zendrouter
Version ^2.0.1
—
—
zendframework/zend-expressive-zendviewrenderer
Version ^1.3
—
—

Weekly Downloads

Info

Last Published
9 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform