Risky to adopt: the package has had no release or repository activity since 2016, so it is effectively unmaintained despite being a properly licensed, tested, and documented module. Use it only if you can accept compatibility and support risks.
42%
Total Score
50
75
50
The latest release was published in March 2016, with no releases in the last 12 months; the earlier eight releases show an initially active project that has since gone quiet for about 10 years.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the long-term lack of maintenance rather than indicating merely a slow release cadence.
The repository is not marked archived, which avoids the strongest abandonment signal, but its last push was in April 2016 and does not offset the absence of recent activity.
No security policy is present, leaving no documented process for reporting vulnerabilities; this adds a transparency concern, especially for a project that has not been maintained recently.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-mvc Version 2.* | — | — |
matryoshka-model/matryoshka Version ~0.8.0 | — | — |
zendframework/zend-modulemanager Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.