The package includes a README, tests, and a BSD-3-Clause license, with no install scripts. Its small footprint and single registry maintainer leave little evidence of ongoing support.
42%
Total Score
25
100
71
83
This package has only one release, published over 12 years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a dependency intended for ongoing use.
The repository recorded no commits and no active maintainers in the last 3 months, and its last push was over 8 years ago. The repository is not archived, but that does not compensate for the prolonged inactivity.
Only one account has registry publish access, leaving a thin publishing base. This is a concern alongside the package's long release and commit inactivity, though registry access alone does not prove active maintenance.
The repository has zero stars, forks, and watchers, providing no supporting evidence of an active user or contributor community. Popularity is not required for health, so this is secondary to the maintenance evidence.
The repository uses Composer for builds, but no security-scanning tool was detected. The missing scanner is a hygiene limitation, not a decisive dependency-health risk for this small package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-log Version >=2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.