Risky to adopt: the package has had no release or repository commits for over 10 years. It remains licensed, documented, tested, and not deprecated or archived, but its long-term abandonment risk outweighs those strengths.
38%
Total Score
50
50
79
83
The package has 17 releases, but none in the last 12 months and the latest release was over 10 years ago. This is strong evidence that maintenance has stopped.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating a high abandonment risk.
The package has six runtime dependencies, all consistent with its PHP framework role; this is a moderate dependency surface but not an excessive one on its own.
There are eight open issues with no new or closed issues and no pull requests in the last month, adding to the evidence of an inactive project.
Composer is used for builds, but no security scanning tools are present. The absence is a modest transparency gap, though the repository has no active workflow surface to assess.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-stdlib Version ~2.4 | — | — |
zendframework/zend-paginator Version ~2.4 | — | — |
zendframework/zend-inputfilter Version ~2.4 | — | — |
zendframework/zend-eventmanager Version ~2.4 | — | — |
zendframework/zend-servicemanager Version ~2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.