The MIT license and included README make the package easier to evaluate, while Composer packaging is straightforward. Missing security scanning and a security policy leave limited evidence of ongoing maintenance discipline.
38%
Total Score
25
100
75
75
The package has only two releases, both from February 2023, and none in the last 12 months despite being about 3.6 years old. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No provided signal shows compensating maintenance activity.
Only one registry maintainer is listed, leaving little observable publishing capacity if that person becomes unavailable. The repository is user-owned rather than organization-backed, so there is no provided organizational compensation.
The repository has zero stars and forks and only one watcher, providing little evidence of community adoption or external oversight. Popularity is supporting evidence, but this reinforces the maintenance concerns.
Composer build tooling is present, but no security-scanning tools are configured. The build setup is a positive, while the absent scanning reduces confidence in ongoing project hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nio/zeero-framework Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.