Testing, licensing, and release notes are in place. The small dependency set and lack of install-time scripts reduce integration friction.
67%
Total Score
75
100
94
75
The package has 10 releases over about 8 years, with one release in the last 12 months and a median interval of about 10 months. A recent release helps, but the long cadence limits evidence of active maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months. The recent release and organization backing provide some context, but they do not show ongoing development activity.
No security policy is present. This is a transparency gap for reporting vulnerabilities, though it is not by itself evidence of unsafe code.
Both workflows were analyzed without untrusted checkouts or script-injection findings, but all five action references are unpinned and a high-confidence bot-condition finding affects the auto-merge workflow. These are workflow hygiene and supply-chain maintenance concerns, not a severe risk on their own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diablomedia/zendframework1-view Version ^1.0.5 | — | — |
diablomedia/zendframework1-controller Version ^1.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.