Package Health

diablomedia/zendframework1-ldap

Its narrow repository footprint and missing security policy reduce transparency for long-term maintenance. Licensing, tests, release notes, dependency scope, and an unarchived organization-backed project provide useful counterweight.

Latest 1.0.9PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The project has released 10 versions since May 2018, including one in the last 12 months, but its median interval is about 325 days, indicating a slow maintenance cadence.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months, a concrete sign that current maintenance activity has slowed.

Security policycaution

No security policy was found in the repository, leaving vulnerability-reporting and response expectations undocumented.

Workflow auditcaution

All five analyzed action references are unpinned, and one workflow has top-level write permissions; the audit also found a high-confidence bot-condition issue. No untrusted checkout or script-injection sink was found, so this is workflow hygiene risk rather than a severe standalone dependency risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
diablomedia/zendframework1-date
Version ^1.0.5
—
—
diablomedia/zendframework1-crypt
Version ^1.0.8
—
—
diablomedia/zendframework1-config
Version ^2.0.5
—
—
diablomedia/zendframework1-exception
Version ^1.1.1
—
—

Weekly Downloads

Info

Last Published
8 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform