A complete README and MIT license make adoption clearer, but the five runtime dependencies and absent security policy offer little extra confidence. Choose a maintained Yii2 file component instead.
12%
Total Score
0
40
50
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning against taking a new dependency on it.
The package has had no release in about 11 years and no releases in the last 12 months. Its earlier 12-release history does not compensate for this prolonged inactivity.
There were zero commits and zero active maintainers in the last three months, consistent with the archived repository and long release gap.
The source repository is archived, and its last push was about 10 years ago. Archived source leaves little realistic prospect of maintenance or fixes.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This adds concern, although the package's abandonment is the more serious issue.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
yiisoft/yii2-jui Version * | — | — |
flexibuild/component Version * | — | — |
yiisoft/yii2-imagine Version * | — | — |
bower-asset/blueimp-file-upload Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.