Package Health

zf1s/zend-session

Usable with caveats: it has a long release history, a recent stable release, an active organization-owned repository, and no deprecation or archive warning. Maintenance is thin, with only one commit from one contributor in the last three months and no tests or security policy.

Latest 1.16.2PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Package scaffoldingcaution

A README is present, but neither the artifact nor the repository includes tests or a changelog. The README directs maintenance to the main repository, but the collected repository evidence does not show those missing quality and change-tracking artifacts being covered.

Repo bus factorcaution

All of the 1 commit in the last three months came from one contributor, giving that contributor a 100% share. Although organization ownership provides some handoff support, the observed activity remains highly concentrated.

Repo commit activitycaution

The repository recorded 1 commit and 1 active maintainer in the last three months. Recent activity exists, but the very low volume indicates limited maintenance capacity.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tool is configured. The missing scanning is a genuine supply-chain hygiene gap, while Composer provides basic package build structure.

Security policycaution

The repository has no security policy. This reduces transparency about how vulnerabilities are reported and handled.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
zf1s/zend-exception
Version ^1.16.2

Weekly Downloads

Info

Last Published
5 days ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform