Risky to adopt for new projects: the package has had no release or repository commit activity for about nine years. It is clearly packaged, licensed, stable, and not deprecated or archived, but its maintenance appears effectively stopped.
43%
Total Score
33
100
83
90
The repository had zero commits and zero active maintainers in the last three months, on top of a last push about nine years ago. This is the strongest evidence that fixes and maintenance should not be expected.
The repository owner matches the registry namespace, which supports a consistent ownership link. The owner is identified as a user rather than an organization, so there is no demonstrated organizational maintenance capacity.
There have been 18 releases since 2014, but the latest release was about nine years ago and there were no releases in the last 12 months. That indicates a materially stale maintenance cycle, even though the historical release record is established.
There were no new issues or pull requests in the last month and no merged pull requests, consistent with an inactive project. The unknown open-issue count limits how fully this can be interpreted.
The repository has zero stars, two forks, and one watcher, providing little supporting evidence of active community attention. Low popularity alone is not decisive for a small component package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
zf1/zend-exception Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.