Package Health

zf3fans/zf3-user-c11n

Risky to adopt without further verification. It has had no release in nearly two years, lacks a declared source repository, and its README is still an untouched Bitbucket tutorial rather than package documentation. The stable version and absence of install scripts help, but do not offset the weak transparency and maintenance evidence.

Latest 1.0.2PackagistPackagist

43%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

60

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historydanger

Only three releases exist, with none in the last 12 months and the latest release nearly two years ago. This is meaningful evidence of slowing or stopped maintenance, especially because no repository activity is available to compensate.

Dependency profilecaution

Six runtime dependencies, including framework, mail, HTTP, and extension requirements, create some maintenance surface but are not excessive for the package’s apparent functionality.

Licensecaution

The package declares a proprietary license in its manifest, so it is licensed, but that is restrictive and provides no license file for additional clarity to users of an open-source dependency.

Package scaffoldingcaution

A README is present, but its 2,610 characters are an unedited Bitbucket tutorial and do not explain this package; the absence of packaged tests and a changelog is expected and is not itself a gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
zf3fans/zf3-lib
Version ^1.0
guzzlehttp/guzzle
Version ^6.5
laminas/laminas-mvc
Version ^3.7
phpmailer/phpmailer
Version ^v6.8

Weekly Downloads

Info

Last Published
1 year ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform