There is no license declaration or license file, and the repository has no security policy or automated security scanning. The package has a README and is not archived, but those positives do not address maintenance risk.
32%
Total Score
0
50
50
This package has only one release, published over 13 years ago, with no releases in the last 12 months. That strongly indicates the dependency is no longer maintained.
There were zero commits and zero active maintainers in the last three months. Combined with the old single-release history, this is strong evidence of abandonment.
No license is declared, no license file is present in the artifact, and the linked repository also has no license file. Developers lack clear permission to use and redistribute the code.
The repository uses Composer, but has no security-scanning tools. For an old library with no recent activity, that leaves an additional transparency and maintenance gap.
The repository has no security policy. This is a smaller concern than the lack of maintenance, but it provides no documented route for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
joacub/at-base Version * | — | — |
zendframework/zendframework Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.