Its license, documentation, tests, and repository linkage are clear. The package is abandoned and deprecated, with no recent releases or commits; use laminas/laminas-mail instead.
12%
Total Score
33
50
75
Packagist marks the entire package as abandoned and names laminas/laminas-mail as its replacement, making continued adoption a severe lifecycle risk.
The last registry release was on June 7, 2018, with zero releases in the last 12 months despite a substantial historical release history, indicating prolonged abandonment.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the archived and deprecated status.
The linked repository is archived, with its last push on January 30, 2020; archived source is a strong abandonment signal.
The repository is organization-owned, which supports historical project backing, but it does not compensate for the package's current deprecation and archived state.
| Title | Versions | Severity |
|---|---|---|
CVE-2016-10034 zendframework/zend-mail is vulnerable to Improper Neutralization of Special Elements used in a Command ('Command Injection') in versions 0.0.0 - 2.4.11, 2.5 - 2.5.2, 2.6 - 2.6.2 and 2.7 - 2.7.2. | 0.0.0 - 2.4.112.5 - 2.5.22.6 - 2.6.2 +1 more | Critical |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
true/punycode Version ^2.1 | — | — |
zendframework/zend-mime Version ^2.5 | — | — |
zendframework/zend-loader Version ^2.5 | — | — |
zendframework/zend-stdlib Version ^2.7 || ^3.0 | — | — |
zendframework/zend-validator Version ^2.10.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.