Maintenance is quiet, with no commits in the last three months, and the workflows use unpinned actions with a high-confidence bot check warning. A current release, organization backing, tests, licensing, and a documented build provide useful counterweight.
67%
Total Score
75
94
67
The package has existed since 2018 with 10 releases and one release in the last 12 months; the roughly 315-day median interval indicates slow maintenance rather than rapid development. The latest release is recent enough to offset a stronger abandonment concern.
The repository recorded 0 commits and 0 active maintainers in the last three months, which raises maintenance and abandonment concerns. The recent release and repository push show the project is not clearly abandoned, but ongoing activity remains limited.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. Dependabot scanning and the tested repository provide some compensating project hygiene, but not a published response process.
All 5 analyzed action references are unpinned, and the audit found a high-confidence bot-conditions issue; one workflow also grants top-level write access. No untrusted checkout or script-injection path was found, limiting this to workflow hygiene and supply-chain caution.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diablomedia/zendframework1-config Version ^2.0.5 | — | — |
diablomedia/zendframework1-loader Version ^1.0.5 | — | — |
diablomedia/zendframework1-validate Version ^1.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.