Tests, release notes, and clear licensing make this a well-documented package with a credible maintenance baseline. Recent inactivity and broad, unpinned workflow permissions add meaningful upkeep and release-process risk.
68%
Total Score
50
100
50
There were zero commits and zero active maintainers in the last three months, which raises maintenance and abandonment concerns; the recent release and repository push provide only partial compensation.
The linked repository has no security policy, leaving vulnerability reporting and response expectations less transparent for a library with many runtime dependencies.
All five action uses are unpinned, one workflow grants top-level write permissions, and a high-confidence bot-condition finding affects the Dependabot auto-merge workflow. No untrusted checkout or script-injection path was found, so this is workflow hygiene risk rather than a severe standalone defect.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diablomedia/zendframework1-http Version ^1.0.5 | — | — |
diablomedia/zendframework1-json Version ^1.0.7 | — | — |
diablomedia/zendframework1-filter Version ^1.0.8 | — | — |
diablomedia/zendframework1-loader Version ^1.0.5 | — | — |
diablomedia/zendframework1-locale Version ^1.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.