Usable with caveats: it is a stable, actively published package with organizational backing and a clear license. The source repository has only one active contributor recently, with no tests, changelog, or security policy, so maintenance transparency is limited.
73%
Total Score
67
50
88
90
The package declares 11 runtime dependencies, including several related zf1s components and PHP extensions; this is a meaningful dependency surface but is coherent for a framework REST component.
The artifact and repository include a README but neither includes tests or a changelog. The README explains that this is an automatically split package and points users to a main repository, which partly explains the sparse artifact but does not cover the missing repository testing evidence.
One contributor made all commits in the last three months, creating a concentrated maintenance risk. Organizational ownership provides some handoff capacity, so this is caution rather than a severe risk.
Only one commit was recorded in the last three months, showing limited recent development activity; the recent release history provides some compensation but not evidence of broad ongoing work.
Composer is used for builds, but no security scanning tool is present. For a small library this is a hygiene gap, though it is not by itself evidence of abandonment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
zf1s/zend-uri Version ^1.16.2 | — | — |
zf1s/zend-xml Version ^1.16.2 | — | — |
zf1s/zend-http Version ^1.16.2 | — | — |
zf1s/zend-server Version ^1.16.2 | — | — |
zf1s/zend-service Version ^1.16.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.