Clear licensing, tests, and release notes make the package easy to evaluate and maintain. Its small user base and inactive recent development leave less evidence of ongoing support.
68%
Total Score
67
100
94
75
The package has existed for about 8 years with 10 releases and one release in the last 12 months. The roughly 311-day median interval shows a slow cadence, but the recent release provides evidence of continued publishing.
There were no commits and no active maintainers in the last three months, which is a real support concern. The recent release and repository push partly compensate but do not demonstrate sustained development.
There are no open issues and five open pull requests, with no pull requests merged in the last month. The lack of merged work reinforces the weak recent maintenance signal.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for users of this dependency.
All five analyzed action references are unpinned, and one workflow grants top-level write access. The audit also found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow; these are workflow hygiene and supply-chain maintenance concerns, not evidence that the package itself is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diablomedia/zendframework1-uri Version ^1.0.5 | — | — |
diablomedia/zendframework1-validate Version ^1.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.