Healthy and usable, with some maintenance caveats. It has a long release history, a current stable release, active recent publishing, and organization backing, but repository activity is concentrated in one contributor and there are no tests, changelog, or security policy.
78%
Total Score
67
100
88
75
The artifact and repository include a README but neither contains tests or a changelog. For a mature library, the absence of both reduces transparency and makes regression assessment harder.
All recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown, leaving maintenance dependent on a single person in the observed period.
There was one commit in the last 3 months from one active maintainer, showing recent activity but only limited ongoing development.
The repository uses Composer for builds, which supports reproducible package management, but no security scanning tool is present. The missing scanner is a transparency gap rather than evidence of unsafe code.
The repository has no security policy. This weakens the documented process for reporting and handling vulnerabilities, though it is not by itself evidence of abandonment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
zf1s/zend-crypt Version ^1.16.2 | — | — |
zf1s/zend-loader Version ^1.16.2 | — | — |
zf1s/zend-validate Version ^1.16.2 | — | — |
zf1s/zend-exception Version ^1.16.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.