The MIT license, tests, and README support straightforward integration. Organization backing and a non-archived repository add some continuity, but the documentation explicitly says not to use it in production.
40%
Total Score
75
70
75
The latest release was published in May 2017, about 9 years ago, and there were no releases in the last 12 months. The four-release history shows an established package but strongly indicates abandonment risk.
The package includes a README and tests, which support adoption, but the README explicitly labels the project a work in progress and says not to use it in production. No changelog is not a concern because changelogs belong in the source project.
The repository has no open issues or pull requests and recorded no issue or pull-request activity in the last month. Combined with the old release date, this provides little evidence of active maintenance.
No repository security policy was found. This is a modest transparency gap, though the package's primary concern is its long inactivity rather than evidence of an active security response failure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
xloit/xloit-std Version ^0.0 | — | — |
xloit/xloit-exception Version ^0.0 | — | — |
zendframework/zend-i18n Version ^2.7 | — | — |
zendframework/zend-soap Version ^2.6 | — | — |
zendframework/zend-stdlib Version ^2.7 || ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.