The package includes a usable README, repository tests, an explicit MIT license, and a repository that matches the package. It has no security policy or scanning, so maintenance transparency is limited.
40%
Total Score
100
64
75
Only two releases were published, both in March 2017, with no releases in the last nine years. That long period without a release is strong evidence of abandonment risk.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools are configured. This is a modest supply-chain hygiene gap rather than evidence of abandonment by itself.
The linked repository is not archived, so the project has not been formally retired. However, its last push was roughly nine years ago, which limits the reassurance this provides.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. No other provided signal compensates for that transparency gap.
The latest version is v0.2 rather than a stable major release, which suggests an immature project; the absence of prerelease labeling provides only limited compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.6 | — | — |
trntv/cheatsheet Version ^0.1@dev | — | — |
vlucas/phpdotenv Version ^2.0 | — | — |
yiisoft/yii2-bootstrap Version ^2.0.0 | — | — |
yiisoft/yii2-authclient Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.