Risky to adopt: the package has had no release or repository activity for nearly 10 years, and its documentation remains unfinished. It is licensed, tested, and backed by a matching organization repository, but those positives do not offset the strong abandonment risk.
42%
Total Score
50
64
83
The latest release was published nearly 10 years ago, with no releases in the last 12 months. This is strong evidence that the package is no longer actively maintained.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap and indicating substantial abandonment risk.
The package includes a README, tests, and release notes for this version, which supports basic transparency and quality. However, the README marks configuration and usage as work in progress, limiting its usefulness to consumers.
There are no open issues or pull requests, and no recent issue or pull-request activity. This is consistent with an inactive project, although the lack of backlog is not itself a severe problem.
Composer is used for builds, but no security scanning tools are configured. For an old, inactive package this is a meaningful transparency gap, though it is less serious than the missing maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zendxml Version ~1.0-dev | — | — |
zfcampus/zf-api-problem Version ~1.0 | — | — |
zendframework/zend-stdlib Version 2.* | — | — |
matryoshka-model/matryoshka Version ~0.8.0 | — | — |
matryoshka-model/service-api Version ~0.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.