The project has no commits in the last three months, despite a recent release, and its automation has a high-confidence bot-condition issue with all five actions unpinned. Licensing, tests, release notes, dependency tooling, and organization backing provide useful support.
65%
Total Score
67
100
94
75
The package has existed for about 8 years with nine releases, but only one release in the last 12 months and a median interval of about 344 days indicate slow maintenance.
There were zero commits and zero active maintainers in the last three months, a concrete sign of currently paused maintenance and increased abandonment risk.
There are no open issues but five open pull requests, with no issues or pull requests merged in the last month; this suggests unresolved maintenance work.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The audit found a high-confidence bot-condition issue in the auto-merge workflow, all five action references are unpinned, and one workflow grants top-level write access. The workflows were fully analyzed and no untrusted checkout or script-injection sink was found, so this is a hygiene and workflow-integrity concern rather than a severe standalone health verdict.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diablomedia/zendframework1-uri Version ^1.0.5 | — | — |
diablomedia/zendframework1-http Version ^1.0.5 | — | — |
diablomedia/zendframework1-crypt Version ^1.0.8 | — | — |
diablomedia/zendframework1-config Version ^2.0.5 | — | — |
diablomedia/zendframework1-exception Version ^1.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.