The MIT license, README, and comprehensive tests make the package easier to evaluate and integrate. Its security documentation is thin, and ongoing maintenance depends on one contributor.
58%
Total Score
50
79
75
The latest registry release was published nearly eleven years ago, with only four releases and none in the past year. This is strong evidence of a dormant release line despite the repository being recently updated.
The repository is owned by an individual user rather than an organization, so the single-maintainer and single-contributor findings are not visibly backed by a larger project structure.
All recent commits came from one contributor, giving the repository a complete single-contributor concentration. The linked owner is an individual rather than an organization, so there is no provided backing signal to compensate for that concentration.
Only one commit was recorded in the past three months, with one active maintainer. This indicates very limited current maintenance capacity.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nocarrier/hal Version ~0.9 | — | — |
zendframework/zend-http Version ~2.4 | — | — |
zendframework/zend-modulemanager Version ~2.5 | — | — |
zendframework/zend-servicemanager Version ~2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.