Clear licensing, tests, and release notes improve transparency. The linked organization and matching repository add ownership evidence, but the small footprint offers little support beyond the original release.
42%
Total Score
50
71
75
This is the package's only release, published about 10 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk despite the package remaining undepricated.
The repository had zero commits and zero active maintainers in the last three months, consistent with the roughly 10-year-old release and providing no evidence of current maintenance.
One star, zero forks, and zero watchers show very limited adoption and community support. Popularity is supporting evidence rather than decisive on its own, so this adds caution rather than danger.
The repository is not archived, which avoids the strongest abandonment signal, but its last push was about 10 years ago and does not offset the absent recent commits.
No security policy was found, leaving vulnerability reporting and response expectations undocumented. The package's tests and license improve general transparency but do not cover this gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-filter Version ~2.5 | — | — |
zendframework/zend-stdlib Version ~2.5 | — | — |
zendframework/zend-servicemanager Version ~2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.