The package includes a clear README, tests, and BSD licensing, with no install-time scripts or registry deprecation. Its source has seen no commits in over eight years and the package has had no release in over twelve years, making future compatibility and maintenance a serious concern.
45%
Total Score
50
50
69
75
Only two releases were published, both in December 2013, with no releases in the last twelve months; the long release gap is a major abandonment concern.
There were no commits and no active maintainers in the last three months, consistent with a repository that has been inactive since 2017 and materially increasing abandonment risk.
Three runtime dependencies, including PHP and two Zend Framework components, indicate a modest dependency surface, though the old ecosystem context may limit compatibility.
Composer is used for builds, showing basic project tooling, but no security-scanning tools are present. This is a minor transparency and maintenance gap rather than a severe risk.
The linked repository is not archived, but its last push was in October 2017; the non-archived status only partly offsets the stale source.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-uri Version 2.* | — | — |
zendframework/zend-stdlib Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.