Package Health

diablomedia/zendframework1-mail

A stable BSD-licensed component has tests, release notes, and an organization-backed repository. Its dependency set is substantial but structured, and automated dependency scanning is present.

Latest 1.0.9PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitycaution

The repository had zero commits and zero active maintainers in the last three months. Although a recent package release provides some evidence of upkeep, the current activity gap raises abandonment risk.

Repo issue activitycaution

There are five open pull requests but no issues or pull requests were merged in the last month. This suggests pending maintenance work without recent evidence of resolution.

Security policycaution

The repository has no security policy. This is a transparency gap for a component handling mail protocols, although it does not by itself show that maintenance has stopped.

Workflow auditcaution

The audit completed all two workflows and found no untrusted checkouts or script injection, but all five action references are unpinned and a high-confidence bot-conditions finding affects the auto-merge workflow. One workflow also grants top-level write permissions, increasing hygiene and supply-chain risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
diablomedia/zendframework1-date
Version ^1.0.5
—
—
diablomedia/zendframework1-mime
Version ^1.0.5
—
—
diablomedia/zendframework1-config
Version ^2.0.5
—
—
diablomedia/zendframework1-loader
Version ^1.0.5
—
—
diablomedia/zendframework1-validate
Version ^1.0.5
—
—

Weekly Downloads

Info

Last Published
8 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform