Testing, a README, and release notes improve day-to-day adoption. Organization backing and a clean install profile provide some continuity, but the repository’s safeguards are uneven.
62%
Total Score
75
50
94
50
Six runtime dependencies make this component part of a broader set of coupled Zend Framework packages, increasing upgrade coordination compared with a standalone library.
The package has existed for over 8 years with 11 releases, but only one release in the last 12 months and a median interval of about 298 days indicate a slow maintenance cadence.
There were zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern, although the recent release and repository push provide limited compensating evidence.
No security policy is present, leaving vulnerability-reporting and response expectations undocumented.
All five action references are unpinned, and a high-confidence bot-conditions finding reports that actor context may be spoofable in the auto-merge workflow. Top-level write permissions in one workflow add further hygiene risk, though no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diablomedia/zendframework1-json Version ^1.0.7 | — | — |
diablomedia/zendframework1-view Version ^1.0.5 | — | — |
diablomedia/zendframework1-config Version ^2.0.5 | — | — |
diablomedia/zendframework1-layout Version ^1.0.6 | — | — |
diablomedia/zendframework1-controller Version ^1.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.