Clear documentation, tests, and release notes make integration straightforward. The MIT license and organization ownership add useful continuity.
68%
Total Score
67
50
88
75
The package has three runtime dependencies, all within the same Zolta component family; this is reasonable for an umbrella package but creates some dependency-chain reliance.
The package is only 46 days old with two releases, so its maintenance record is still limited despite a recent release cadence of about 6 days.
One contributor made all five recent commits, creating a concentrated maintenance risk; organization ownership provides some ability to hand off maintenance but does not remove the concentration.
Five commits were made in the last three months, showing recent activity, but the short history limits evidence of sustained maintenance.
Composer build tooling is present, but no security scanning tool was detected, leaving security-process maturity unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zolta/cqrs Version ^2.1 | — | — |
zolta/http Version ^2.1 | — | — |
zolta/forge Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.