The package is compact, documented, and has a clear MIT license. Its direct Yii2 and PDO_OCI dependencies are straightforward, but the repository shows no security tooling or policy.
38%
Total Score
0
100
75
75
This is the sole release, published about 9 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk for a database integration package.
The repository has had 0 commits and 0 active maintainers in the last 3 months, consistent with its last push being about 9 years ago. No newer activity compensates for this.
The repository has 0 stars and 0 forks, with 1 watcher. This is weak supporting evidence of adoption, but popularity alone does not determine package health.
Composer is used for builds, but no security-scanning tooling is present. That is a transparency and maintenance-hygiene gap, though it is secondary to the long inactivity.
The linked repository has no security policy. For a database connectivity library, that leaves vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.