The package has a clear README, a license file, and a small dependency set. Those positives do not offset its lack of ongoing maintenance and explicit recommendation to use another module.
18%
Total Score
0
50
50
50
The README explicitly states that the module is unmaintained and recommends HtSession instead, although the release includes a README and release notes. This is a direct adoption concern.
Only two releases were published, with the latest on May 26, 2014, and none in the last 12 months. The long period without releases strongly indicates abandonment.
The repository had zero commits and zero active maintainers in the last three months, consistent with the package's stated unmaintained status.
The package declares three runtime dependencies, including PHP, Zend Framework, and ZfcUser. This is a limited dependency surface, though the dependencies are tied to an old framework ecosystem.
The repository has no security policy. This is a transparency gap, especially for an authentication-related module, though the much more serious concern is the project's abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zf-commons/zfc-user Version >=0.1,<2.0 | — | — |
zendframework/zendframework Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.