The package is clearly identified and licensed, with a matching repository and a readable installation guide. Its repository has had no recent commits and its last release was over ten years ago, making ongoing fixes unlikely.
35%
Total Score
0
100
71
75
The package has 12 releases, but all were concentrated around its January 2016 launch; there have been no releases in the last ten years. That long gap is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last three months, consistent with the release history and indicating no current maintenance capacity.
The repository has 0 stars and 0 forks with only 1 watcher, providing little evidence of an active user or contributor community. Popularity is supporting evidence, so this reinforces but does not determine the score.
Composer is used as the build tool, but no security scanning tool is present. The missing scanner is a modest transparency gap, not evidence that the package is unsafe to use.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a minor transparency concern alongside the much larger maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zendframework Version >=2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.