Clear licensing and a matching organization-owned repository make the package easy to identify and reuse. Its documentation says it is no longer actively maintained, with no releases since July 2017 and no recent commits.
30%
Total Score
25
58
50
The package includes a usable README, and the absence of tests or a changelog is normal for a published artifact. However, the README explicitly states that the module is no longer actively maintained, which materially raises adoption risk.
The latest release was published in July 2017, and there have been no releases in roughly nine years. That is strong evidence of abandonment for a dependency intended for ongoing use.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history and the project's own maintenance warning.
The repository is owned by the symbiote-library organization, providing some ownership context. That backing does not show current development activity.
The repository is not archived, which avoids the strongest formal abandonment signal, but its last push was still in July 2017. This does not compensate for the long period without development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/framework Version 3.* | — | — |
zendframework/zend-feed Version ~2.2.0 | — | — |
zendframework/zend-http Version ~2.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.