It includes tests, a matching license, clear source files, and a recent release with PHP 8.5 support. Maintenance has paused for three months, while all workflow actions are unpinned and a high-confidence bot check is flagged.
64%
Total Score
75
100
100
75
There were no commits and no active maintainers in the last three months, which is a meaningful maintenance concern despite the recent release and repository push.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is not by itself evidence of abandonment.
All five analyzed action references are unpinned, and the audit found a high-confidence bot-conditions issue in the auto-merge workflow. One workflow also grants top-level write permissions; without an untrusted trigger or checkout this remains workflow hygiene risk rather than a severe supply-chain finding.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diablomedia/zendframework1-config Version ^2.0.5 | — | — |
diablomedia/zendframework1-loader Version ^1.0.5 | — | — |
diablomedia/zendframework1-exception Version ^1.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.