Usable with caveats: the release is licensed, tested, stable, and backed by an active-looking organization repository, but recent maintenance activity is currently absent and the release cadence is slow. Workflow permission gaps and the lack of a security policy add smaller transparency concerns.
62%
Total Score
75
50
94
75
Six runtime dependencies, including several related Zend Framework components, create a meaningful dependency surface for a small component. The dependencies are thematically consistent with the package, so this is a manageable rather than severe concern.
The package has existed for over 8 years with 9 releases, but only one release in the last 12 months and a median interval of about 340 days indicate slow maintenance. The latest release is still recent enough to avoid an abandonment verdict.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although the release and a repository push occurred earlier, the current lack of observed development lowers confidence in ongoing maintenance.
No repository security policy was found. This is a transparency gap for reporting vulnerabilities, though it is not by itself evidence that the package is unsafe.
One workflow has no top-level token permissions and another grants top-level write access. Explicit least-privilege permissions would provide stronger workflow hygiene, despite the absence of other dangerous workflow patterns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diablomedia/zendframework1-http Version ^1.0.5 | — | — |
diablomedia/zendframework1-json Version ^1.0.7 | — | — |
diablomedia/zendframework1-config Version ^2.0.5 | — | — |
diablomedia/zendframework1-service Version ^1.0.4 | — | — |
diablomedia/zendframework1-validate Version ^1.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.