The release includes tests, a matching MIT license, and release notes for version 1.2. Its small dependency surface and clear repository match help, but there is no recent project activity or security policy.
38%
Total Score
0
100
71
50
The package has had no release in more than 13 years, with only three releases overall and none in the last 12 months. This is strong evidence of abandonment for a dependency that may need maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last release being in 2013. The lack of recent activity materially increases maintenance risk.
The repository has zero stars and forks and one watcher, providing little evidence of a broader support community. Popularity is only supporting evidence, so this reinforces rather than determines the abandonment concern.
The repository is not archived, which avoids an explicit abandonment marker, but it was last pushed in October 2013. The repository state therefore offers little compensation for the long release gap.
The linked repository has no security policy. For a package containing reusable cache components, that weakens vulnerability-reporting transparency, although the old and inactive project is the larger concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hearstuk/zf1-components-base Version ~1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.