The package includes tests, release notes, a clear license, and active organization backing. Recent repository activity is absent, while the workflows use unpinned actions and contain a high-confidence bot-condition warning.
62%
Total Score
75
50
94
50
The release has six runtime dependencies within the same maintained-looking component family plus PHP. This is a meaningful dependency surface, but it is coherent rather than unusually broad.
The package has 10 releases since March 2018 and one release in the last 12 months, including a latest release on January 13, 2026. The roughly yearly median release interval indicates modest rather than rapid maintenance.
There were zero commits and zero active maintainers in the last three months. The recent release and organization backing partly offset this, but the current maintenance pace remains uncertain.
No repository security policy was found. This is a transparency and reporting gap, though it is not by itself evidence of abandonment.
All five action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The workflows had no untrusted checkout or script-injection findings, so this is a real hygiene concern rather than a severe release risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diablomedia/zendframework1-json Version ^1.0.7 | — | — |
diablomedia/zendframework1-text Version ^1.0.5 | — | — |
diablomedia/zendframework1-config Version ^2.0.5 | — | — |
diablomedia/zendframework1-session Version ^2.0.0 | — | — |
diablomedia/zendframework1-exception Version ^1.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.