Usable with caveats: it has a stable release line, recent publishing activity, an active organization-owned repository, and clear licensing. Maintenance is concentrated in one contributor, with no tests, changelog, or security policy provided, so it is better suited to projects comfortable with legacy code than to critical new dependencies.
72%
Total Score
67
100
88
75
The artifact and repository include a README but no tests or changelog. The README directs issue reporting and pull requests to the main repository, but no provided signal compensates for the missing validation and change history.
All recent commits came from one contributor, creating a real continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is shown in this signal.
The repository recorded one commit in the last 3 months from one active maintainer. Recent activity exists, but the very low volume provides limited evidence of sustained maintenance.
The repository uses Composer for builds, which supports reproducible package management, but it reports no security scanning tools.
No repository security policy is present, leaving vulnerability-reporting expectations unclear for a package that handles cloud service integrations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
zf1s/zend-xml Version ^1.16.2 | — | — |
zf1s/zend-service Version ^1.16.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.