Package Health

diablomedia/zendframework1-view-helper-url

Zend Framework 1 View_Helper_Url component

Latest 1.0.9PackagistPackagist

62%

Total Score

caution

Usable with caveats: no commits in three months and workflow automation has high-confidence bot-condition and pinning concerns.

Health Score Breakdown

Release historycaution

The package has existed since March 2018 with 10 releases and one release in the last 12 months, but its median release interval is about 317 days. This indicates a mature but slow release cadence.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the recent release and repository push provide some compensating evidence.

Security policycaution

The repository has no security policy. This is a transparency gap for reporting and handling vulnerabilities, though it does not by itself show abandonment.

Workflow auditcaution

All five analyzed action references are unpinned, and the audit found a high-confidence bot-conditions issue in Dependabot auto-merge where actor context may be spoofable. There were no untrusted checkouts or script injections, so this is a workflow-hygiene concern rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
diablomedia/zendframework1-view
Version ^1.0.5
—
—
diablomedia/zendframework1-controller
Version ^1.0.6
—
—

Weekly Downloads

Info

Last Published
8 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform