Clear licensing, tests, and release notes make this package straightforward to inspect and maintain. The small repository footprint and lack of security policy leave less assurance, while the workflow's unpinned actions add a modest supply-chain hygiene concern.
68%
Total Score
50
100
94
75
The repository recorded zero commits and zero active maintainers in the last 3 months, despite three registry releases in the last year; that mismatch weakens evidence of active source maintenance.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
No repository security policy is present, so vulnerability reporting and response expectations are not documented.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its two action references are unpinned, leaving them exposed to upstream changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
maksimovic/zend-loader Version ^2.0 | — | — |
maksimovic/zend-validate Version ^2.0 | — | — |
maksimovic/zend-exception Version ^2.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.