It has a clear BSD-3-Clause license, a useful README, tests, and release notes for this version. Its small dependency set and lack of install scripts limit complexity, but they do not offset the maintenance risk.
38%
Total Score
25
100
70
75
The latest release was about 13 years ago, with no releases in the last 12 months. That long period without published updates is a substantial abandonment concern.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the very old release history. This materially increases the risk that defects and ecosystem changes will go unaddressed.
There are six open issues, with no new or closed issues and no pull-request activity in the last month. The unresolved queue adds to the evidence of an inactive project.
The repository has no security policy. This is a transparency and response-process gap, though it is secondary to the much stronger evidence of prolonged inactivity.
The assessed release is still a beta, and all recent releases were prereleases. This leaves maturity and long-term compatibility less certain.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-http Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.