Usable with caveats: this is a clearly identified, licensed, stable package with a complete readme and no install scripts, but it has had no release or repository activity since July 2017. Depend on it only if its legacy code and lack of ongoing maintenance fit your needs.
52%
Total Score
50
100
75
75
The package has 18 releases, but the latest was in July 2017 and there were no releases in the last 12 months, indicating prolonged maintenance inactivity.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the release history and indicating no current maintenance capacity.
The repository uses Composer, which provides basic build and dependency tooling, but it has no security scanning tools, leaving a transparency and maintenance gap.
The linked repository is not archived, but its last push was in July 2017, so the non-archived status does not compensate for the long period of inactivity.
No repository security policy is present. This matters for a library that may receive security reports, although the absence is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
zf1/zend-xml Version self.version | — | — |
zf1/zend-http Version self.version | — | — |
zf1/zend-server Version self.version | — | — |
zf1/zend-exception Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.