Usable with caveats: it is a long-established, actively released package with clear licensing and organizational backing. Maintenance is concentrated in one contributor, and the repository has no tests, changelog, or security policy.
72%
Total Score
67
100
88
83
A README explains that this is automatically split from the zf1s monorepo, but neither the artifact nor repository contains tests or a changelog. The split-package format explains some missing documentation, but the lack of visible tests remains a maintenance gap.
All one commit in the last 3 months came from a single contributor. Organizational backing provides some handoff capacity, but no second active contributor is shown, so continuity remains concentrated.
The repository recorded one commit in the last 3 months, showing some current activity but a very low maintenance pace for the period.
Composer is used as a build tool, but no security-scanning tool is reported. The absence of scanning is a transparency gap, though it is not by itself evidence of unsafe code.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
zf1s/zend-config Version ^1.16.2 | — | — |
zf1s/zend-loader Version ^1.16.2 | — | — |
zf1s/zend-registry Version ^1.16.2 | — | — |
zf1s/zend-exception Version ^1.16.2 | — | — |
zf1s/zend-controller Version ^1.16.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.