Usable with caveats: this is a long-lived, actively released package backed by a non-archived organization repository. Adoption carries maintenance risk because only one contributor made the sole recent commit, and neither the package nor repository provides tests or a security policy.
72%
Total Score
67
100
88
50
A README is present, but neither the artifact nor repository contains tests or a changelog. The absence of repository tests leaves a real maintenance and verification gap for a library package.
All recent activity comes from one contributor, creating a concentrated maintenance dependency. Organization backing provides some ability to hand maintenance off, but no second active contributor is shown.
The repository recorded one commit in the last 3 months, showing some recent activity but a very low maintenance pace.
Composer build tooling is present, but no security scanning tools are reported. This is a transparency and upkeep gap, though it is not severe on its own.
No repository security policy is present, reducing transparency around vulnerability reporting and response for a library that integrates cloud service adapters.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
zf1s/zend-http Version ^1.16.2 | — | — |
zf1s/zend-queue Version ^1.16.2 | — | — |
zf1s/zend-loader Version ^1.16.2 | — | — |
zf1s/zend-exception Version ^1.16.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.