The package includes a clear README, tests, MIT licensing, and a repository that matches the package under organizational ownership. Its project activity appears frozen, leaving maintenance and compatibility uncertain for a new dependency.
44%
Total Score
75
75
83
The latest release was published in February 2015, with no releases in the past 12 months. This long gap is strong evidence of abandonment risk, though the package is not marked deprecated.
The repository recorded zero commits and zero active maintainers in the past three months. This confirms that the source project is currently inactive rather than merely having a slow release cadence.
The repository uses Composer for builds, but no security-scanning tooling was detected. This weakens evidence of ongoing maintenance hygiene, while the presence of a build tool provides some basic project structure.
No repository security policy was found. This is a modest transparency gap, although it is less significant than the project's clear inactivity and does not by itself indicate that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zendframework Version ~2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.