Package Health

diablomedia/zendframework1-mime

It includes tests, a README, and release notes for 1.0.9, with a clear BSD-3-Clause license. The repository has no commits in three months, and its workflows contain a high-confidence bot-condition issue and use five unpinned actions.

Latest 1.0.9PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package has 10 releases across about 8 years, with one release in the last 12 months. This shows ongoing publication but a slow cadence, so maintenance evidence is limited.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. That weakens evidence of active maintenance, even though a recent release exists.

Security policycaution

The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it does not by itself show abandonment.

Workflow auditcaution

All five analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The top-level write permission is also broader than ideal, but no untrusted checkout or script-injection sink was found.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
diablomedia/zendframework1-exception
Version ^1.1.1
—
—

Weekly Downloads

Info

Last Published
8 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform