The package is small and easy to audit, with only two runtime dependencies and no install-time scripts. Its organization backing and matching repository help, but it has not shipped or received commits for about two years, and its README is only 10 characters.
57%
Total Score
75
100
71
75
The package includes a README, but it is only 10 characters and provides little consumer guidance. The absence of tests and a changelog in the published artifact is normal packaging practice and is not a concern by itself.
The package has only three releases and none in the last 12 months; the latest release was published about two years ago. This indicates limited and currently inactive release maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the roughly two-year gap since the latest release. That raises abandonment risk despite the repository not being archived.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tooling is configured. The missing scanning is a modest hygiene gap rather than evidence of abandonment on its own.
The repository has no security policy. For this small package this reduces disclosure transparency, but it is not severe enough to determine the overall result.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nelexa/zip Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.