The BSD-3-Clause license, matching repository, and usable README improve transparency. The small codebase, absent tests and security tooling, and no recent maintenance leave long-term support uncertain.
40%
Total Score
50
100
69
100
The latest release was over 8 years ago, with no releases in the last 12 months; the seven-release history shows the project has effectively stopped shipping.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the extended release gap and indicating no current maintenance.
The package includes a README and the repository uses GitHub releases, but it has no tests or changelog; the missing tests reduce maintenance confidence for a session component.
Composer build tooling is present, but no security scanning tooling was detected, leaving a modest transparency and maintenance gap.
The repository is not archived, which is a limited positive sign, but its last push was over 8 years ago and does not offset the lack of current activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-db Version 2.9.* | — | — |
zendframework/zend-mvc Version 3.1.* | — | — |
zendframework/zend-session Version 2.8.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.