MIT licensing, a readable README, and a repository that matches the package make it straightforward to inspect. The lack of security scanning and the very small project footprint provide little additional assurance.
35%
Total Score
0
71
50
The latest release was published in October 2013, nearly 13 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a library dependency.
The repository recorded no commits and no active maintainers in the last three months, while its last push was in December 2014. The long absence of development makes compatibility and defect remediation uncertain.
The repository has 0 stars, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these numbers provide no meaningful external adoption signal to offset the stale maintenance record.
Composer is used for the build, which provides basic project tooling, but no security scanning tools are configured. The tooling is therefore a small positive with limited assurance.
The repository has no published security policy. This is a transparency and response-process gap, especially for a database library, though it is not by itself evidence of a security defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-http Version 2.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.