The BSD-3-Clause license, readable documentation, and repository tests support adoption. There is no deprecation notice or install-time script, but the absent security policy and questionable package-to-repository connection limit transparency.
38%
Total Score
67
79
83
The latest release was in April 2019, about 7 years and 5 months ago, with no releases in the last 12 months. This is strong evidence of abandonment despite a substantial earlier release history.
There were no commits and no active maintainers in the last 3 months, consistent with the long gap since the latest release and increasing abandonment risk.
There were no new or closed issues or pull requests in the last month. With no open work either, this provides little evidence of active maintenance.
The repository name does not match the package name and its README does not mention the package. This raises concern that the source may not actually correspond to the published package.
Composer is used as the build tool, but no security scanning tool is present. The missing scanner is a modest transparency gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-diactoros Version ^1 | — | — |
zendframework/zend-validator Version ^2 | — | — |
zendframework/zend-inputfilter Version ^2 | — | — |
zendframework/zend-servicemanager Version 2.* || 3.* | — | — |
zendframework/zend-config-aggregator Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.