It includes a clear README, an MIT license, and no install-time scripts. However, only one release was published in 2016, and the repository has had no commits in the last three months, indicating substantial abandonment risk.
42%
Total Score
0
50
69
75
The package has only one release, published in July 2016, with no releases in the last 12 months. This is strong evidence of a long-unmaintained dependency.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the one-release history, this indicates that maintenance has effectively stopped.
The package has six runtime dependencies, including framework and translation components. This is a meaningful integration surface for an old package, although the signal does not show dependency vulnerabilities or instability.
The repository has three stars, zero forks, and one watcher. This limited adoption provides little external evidence of ongoing maintenance, but popularity is only supporting evidence.
Composer is used for builds, but no security scanning tooling is present. This is a modest supply-chain hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-mvc Version @stable | — | — |
zendframework/zend-view Version @stable | — | — |
zendframework/zend-config Version @stable | — | — |
saeven/circlical-po-editor Version dev-master | — | — |
saeven/circlical-twig-extractor Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.