The package has had no release or commit activity since June 2018, and the linked repository does not name or mention it. Its tests, documentation, and source license provide useful transparency, but the release identity and long-term maintenance remain serious concerns.
32%
Total Score
50
50
75
The package has 37 releases but none in the last 12 months, with the latest activity on June 7, 2018; this is strong evidence of abandonment for a dependency released as version 3.0.0-alpha.1.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the multi-year release gap and indicating no current maintenance capacity.
The linked repository name does not match the package name and its README does not mention the package, so the source relationship is not clearly established. This raises transparency and provenance concerns.
The artifact includes a LICENSE file and the repository also has one, so licensing is not absent; however, the manifest declares MIT while the detected artifact license is BSD-3-Clause, creating a material mismatch that should be resolved.
The repository uses Composer build tooling, but no security scanning tools are reported. The missing scanning is a secondary hygiene gap rather than the main adoption risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-stdlib Version ^3.1 | — | — |
zendframework/zend-servicemanager Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.