Package Health

zendframework/zend-expressive-tooling

Unfit to use for a new dependency: the package is abandoned and deprecated in favor of mezzio/mezzio-tooling. Its complete lack of recent releases and repository activity outweighs its good documentation, tests, and licensing.

Latest 1.3.0PackagistPackagist

20%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and identifies mezzio/mezzio-tooling as its replacement, making this release unsuitable for new adoption.

Release historydanger

The package has 29 releases overall, but no releases in the last 12 months and its latest release was November 22, 2019; this confirms long-term abandonment rather than a short release pause.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, consistent with the archived repository and deprecated package.

Repository archiveddanger

The source repository is archived, with its last push on January 20, 2020, so active maintenance and future fixes should not be expected.

Repo toolingcaution

The repository uses Composer build tooling, but no security scanning tools are reported; this is secondary to the stronger evidence that the project is no longer maintained.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
symfony/console
Version ^2.8 || ^3.0 || ^4.0 || ^5.0
—
—
zendframework/zend-code
Version ^2.6.3 || ^3.3
—
—
ocramius/package-versions
Version ^1.3
—
—
zendframework/zend-stdlib
Version ^3.1
—
—
zendframework/zend-expressive
Version ^3.0
—
—

Weekly Downloads

Info

Last Published
6 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform