Usable with caveats: it is a mature, actively released stable package backed by an organization and not deprecated. However, the repository has only one recent contributor and provides no tests, changelog, or security policy, limiting transparency and maintenance confidence.
72%
Total Score
67
100
88
75
The package includes a README, but neither the artifact nor repository contains tests or a changelog. The README directs issue reports and pull requests to the main repository, yet the collected repository evidence does not show those supporting materials.
All recent commits came from one contributor, creating a narrow maintenance base. Organization ownership provides some handoff capacity, but no second active contributor was observed in the measured period.
The repository recorded one commit in the last 3 months from one active maintainer. Recent activity is positive, but the very low volume provides limited evidence of sustained maintenance capacity.
Composer is used as a build tool, but no security scanning tools are configured. For this small library the missing scanning is a hygiene gap rather than a severe risk.
The repository has no security policy. This reduces transparency about vulnerability reporting and response, although it does not by itself indicate abandonment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
zf1s/zend-json Version ^1.16.2 | — | — |
zf1s/zend-loader Version ^1.16.2 | — | — |
zf1s/zend-exception Version ^1.16.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.