The organization-backed repository includes extensive tests, release notes for this version, a clear license, and dependency scanning. The small release cadence, recent lack of commits, and workflow hygiene issues leave meaningful maintenance and publishing risk.
62%
Total Score
67
100
94
50
The package has existed for about 8 years with 11 releases, but only one release in the last 12 months and a median interval of about 306 days indicate slow maintenance.
The repository recorded zero commits and zero active maintainers over the last three months, which is a concrete sign of currently limited maintenance capacity.
There are no open issues and five open pull requests, but no pull requests were merged in the last month, offering limited evidence of active follow-through.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
All five action references are unpinned, and a high-confidence audit finding reports spoofable actor context in the Dependabot auto-merge workflow. One workflow also grants top-level write permissions, increasing publishing automation risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diablomedia/zendframework1-xml Version ^1.0.5 | — | — |
diablomedia/zendframework1-file Version ^1.0.5 | — | — |
diablomedia/zendframework1-json Version ^1.0.7 | — | — |
diablomedia/zendframework1-view Version ^1.0.5 | — | — |
diablomedia/zendframework1-crypt Version ^1.0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.