It has a clear BSD-3-Clause license, readable documentation, release notes, and source tests. No install-time scripts or workflow findings add supply-chain concerns, but these strengths do not offset the package’s lack of active support.
12%
Total Score
0
50
75
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning against taking a new dependency on the release.
The package has seven releases but none in the last 12 months; its latest release was more than 10 years ago. This strongly indicates abandonment.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the archived and abandoned status.
The linked repository is archived, and its last push was more than five years ago. Archived source indicates the project is no longer maintained.
Composer and Phing provide build tooling, but no security-scanning tool is present. This is a modest transparency and maintenance gap, not the main reason to reject the release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version 2.* | — | — |
zendframework/zend-mvc Version 2.* | — | — |
zendframework/zend-form Version 2.* | — | — |
zendframework/zend-http Version 2.* | — | — |
zendframework/zend-view Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.