The package includes tests, a substantial README, a clear BSD-3-Clause license, and no install-time scripts. Its long-standing lack of activity and absent security policy make future fixes and maintenance uncertain.
42%
Total Score
63
50
75
83
Although the package had 29 releases with a roughly 10-day median interval, it has had no releases in the last 12 months and its latest release was October 4, 2018, a long maintenance gap.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the release-history evidence of prolonged abandonment risk.
The package declares 12 runtime dependencies, including several framework services; this is a meaningful maintenance surface for an old package, though the signal does not show unresolved or excessive dependency risk.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a dormant project, although the absence of backlog is not independently negative.
Composer build tooling is present, but no security scanning tools are reported, leaving a modest repository hygiene gap for a package handling authentication and access control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-log Version ^2 | — | — |
zendframework/zend-cache Version ^2 | — | — |
zendframework/zend-crypt Version ^2 | — | — |
zendframework/zend-filter Version ^2 | — | — |
zendframework/zend-session Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.