Healthy and currently usable, with a clear repository, recent releases, and organizational backing. The main caveats are minimal repository activity, a single active contributor, and no tests or security policy shown.
78%
Total Score
67
100
83
88
A README is present, but neither the artifact nor repository contains tests or a changelog. For a long-lived library, the missing verification and change-history documentation are genuine transparency gaps.
All recent commits came from one contributor, which creates concentration risk. The organization-owned repository partly compensates because maintenance can potentially be handed off within the organization.
There was one commit in the last 3 months by one active maintainer, so the project is not entirely dormant. However, this is thin recent activity and provides limited evidence of sustained maintenance capacity.
The repository has no stars or forks and only one watcher, offering little community evidence or external review. Low popularity is supporting evidence only and is outweighed here by the recent release history and organizational ownership.
Composer is used as a build tool, but no security scanning tool is present. The missing scanning is a hygiene gap, while the package's basic build process is explicit.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
zf1s/zend-xml Version ^1.16.2 | — | — |
zf1s/zend-http Version ^1.16.2 | — | — |
zf1s/zend-exception Version ^1.16.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.