Healthy and reasonable to adopt, with a small maintenance risk. It has a long release history, four releases in the last year, an active organization-owned repository, and clear licensing, but recent work is limited to one contributor and the project has no tests or security policy.
78%
Total Score
67
100
83
90
The artifact includes a README but no tests or changelog, and the repository likewise has neither. For a small automatically split library this is a transparency and maintenance gap, though the package documentation explains its monorepo-derived structure.
All recent commits came from one contributor, creating a concentrated maintenance dependency. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository recorded one commit by one active maintainer in the last three months. Recent activity exists, but the volume is thin for ongoing maintenance.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little external validation.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning is a hygiene gap, not evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
zf1s/zend-xml Version ^1.16.2 | — | — |
zf1s/zend-loader Version ^1.16.2 | — | — |
zf1s/zend-exception Version ^1.16.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.