It includes tests, a clear BSD-3-Clause license, and release notes for 1.0.9, with an organization-backed repository and no deprecation. Depend on it only if this older Zend Framework component fits your PHP stack.
62%
Total Score
75
100
94
75
The package has existed since March 2018 with 10 releases, but only one release in the last 12 months and a median interval of about 315 days indicate slow maintenance.
There were no commits and no active maintainers in the three months measured, which is a meaningful maintenance concern for a dependency even though a recent release and repository push provide some counterevidence.
No security policy is present in the repository, leaving vulnerability-reporting expectations less transparent.
All five analyzed action references are unpinned, and a high-confidence bot-conditions finding reports spoofable actor context in the auto-merge workflow. The audit completed fully and found no untrusted checkout or script-injection path, so this is a hygiene and workflow-integrity concern rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diablomedia/zendframework1-view Version ^1.0.5 | — | — |
diablomedia/zendframework1-layout Version ^1.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.