Tests, release notes, and organizational ownership provide useful maintenance evidence. Recent repository activity is quiet, while workflow automation has weak pinning and a high-confidence bot check issue. Pin version 1.0.10 if adopting it.
68%
Total Score
75
92
50
The package has 11 releases since 2018 and one release in the last 12 months, with a long median interval of about 316 days. That indicates slow but continuing maintenance rather than abandonment.
The repository recorded zero commits and zero active maintainers in the last three months. Although a recent release and June push provide some compensation, current development activity is quiet.
No repository security policy was found. This is a modest transparency gap, though the presence of Dependabot provides partial security-process evidence.
All five workflow action references are unpinned, and the audit found a high-confidence bot-conditions issue in the auto-merge workflow. The absence of untrusted checkouts and script injection limits the severity, but CI hygiene still lowers confidence in the release process.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diablomedia/zendframework1-exception Version ^1.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.