It includes a matching repository, clear BSD-3-Clause licensing, a README, and tests. The absence of security scanning and current maintenance evidence leaves long-term support uncertain.
47%
Total Score
50
88
75
The package has 18 releases since January 2014, but its latest release was about 9 years ago and it has had no releases in the last 12 months. That long gap materially raises abandonment risk despite the established release history.
There were no commits and no active maintainers in the last 3 months, consistent with roughly 9 years since the last repository push. This leaves current defects and platform changes unlikely to receive attention.
Composer build tooling is present, but no security scanning tools were detected. That weakens ongoing maintenance assurance, especially for a package whose development has stopped.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap, though it is not evidence of a vulnerability itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
zf1/zend-dom Version self.version | — | — |
zf1/zend-layout Version self.version | — | — |
zf1/zend-session Version self.version | — | — |
zf1/zend-registry Version self.version | — | — |
zf1/zend-exception Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.