It includes tests, a README, and release notes for 1.0.9, with a clear BSD-3-Clause license. The repository has no commits in three months, and its workflows contain a high-confidence bot-condition issue and use five unpinned actions.
64%
Total Score
75
94
67
The package has 10 releases across about 8 years, with one release in the last 12 months. This shows ongoing publication but a slow cadence, so maintenance evidence is limited.
There were no commits and no active maintainers in the last three months. That weakens evidence of active maintenance, even though a recent release exists.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it does not by itself show abandonment.
All five analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The top-level write permission is also broader than ideal, but no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diablomedia/zendframework1-exception Version ^1.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.