The package includes a clear README, extensive tests, release notes, and a matching license. Its organization-backed repository and focused dependency set provide useful context, but the available maintenance evidence is very old.
54%
Total Score
75
70
50
The latest release was published on April 23, 2016, with no releases in the last 12 months. This is a substantial maintenance concern despite seven historical releases and a previously regular cadence.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push occurring in 2016. This leaves current maintenance capacity unconfirmed.
Composer is used for builds, but no security scanning tools were detected. The missing scanning is a hygiene gap, while the long period without activity remains the more important concern.
No repository security policy was found. This reduces transparency for reporting issues, although it is a secondary concern compared with the package's stale release and commit history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-stdlib Version 2.* | — | — |
matryoshka-model/matryoshka Version ~0.8.0 | — | — |
zendframework/zend-paginator Version 2.* | — | — |
zendframework/zend-servicemanager Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.