Clear licensing, tests, and release notes make the package easier to assess and maintain. Recent repository activity is quiet, while workflow permissions and bot checks need attention before adoption.
62%
Total Score
75
100
50
The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful maintenance warning for a library, even though the recent release and April push provide some compensating evidence.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap, but it is not evidence that the package is unsafe.
All workflows were analyzed, but five of six action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. One workflow also grants top-level write permissions; without an untrusted checkout or script-injection sink, these remain workflow-hygiene concerns rather than a severe supply-chain verdict.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diablomedia/zendframework1-cache Version ^1.0.6 | — | — |
diablomedia/zendframework1-config Version ^2.0.5 | — | — |
diablomedia/zendframework1-loader Version ^1.0.5 | — | — |
diablomedia/zendframework1-registry Version ^1.0.5 | — | — |
diablomedia/zendframework1-wildfire Version ^1.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.