Package Health

zf1/zend-serializer

Risky to adopt for new projects: the package has had no release or repository activity since July 2017. It is clearly identified, licensed, stable, and has a usable README, but its long abandonment period and lack of current security or maintenance practice make it a liability.

Latest 1.12.20PackagistPackagist

45%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Release historydanger

The latest release was in July 2017, with zero releases in the last 12 months and a median interval of about 344 days. This long period without updates is strong evidence of abandonment risk, despite the package having 18 historical releases.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the last 3 months, consistent with the release history showing no release since July 2017. This materially lowers confidence in ongoing maintenance.

Project backingcaution

The registry namespace and repository owner match, reducing concern that the package is attached to an unrelated project. The owner is a user account rather than an organization, so there is no demonstrated organizational backing to offset the thin maintenance evidence.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, and no pull requests were merged. This is consistent with the broader inactivity evidence, although the open-issues count is unknown.

Repo popularitycaution

The repository has zero stars, one fork, and one watcher. Popularity is only supporting evidence, but these very low figures provide no community signal to compensate for the lack of maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
zf1/zend-xml
Version self.version
—
—
zf1/zend-loader
Version self.version
—
—
zf1/zend-exception
Version self.version
—
—

Weekly Downloads

Info

Last Published
9 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform