Usable with caveats: it has a long release history, a stable current version, recent releases, and organization-backed ownership. The repository shows only one recent contributor and lacks tests, a changelog, and a security policy, so maintenance transparency is thinner than ideal.
72%
Total Score
63
100
88
90
A README is present, but neither the artifact nor repository includes tests or a changelog. The README points to the main repository for issues and documentation, but the provided evidence does not show those gaps are covered.
All recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown, leaving maintenance concentrated.
The repository recorded one commit in the last 3 months from one active maintainer. Recent release activity partly offsets this, but the source shows limited ongoing maintenance capacity.
There were no new or closed issues or pull requests in the last month, and issue totals are unavailable. This provides little evidence of community support, but it is not by itself evidence of abandonment.
Composer build tooling is present, but no security scanning tools are reported. The missing scanning is a transparency gap, though it is less decisive for this small library than maintenance evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
zf1s/zend-json Version ^1.16.2 | — | — |
zf1s/zend-config Version ^1.16.2 | — | — |
zf1s/zend-exception Version ^1.16.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.