The package is small, clearly matched to its repository, and has a declared MIT license with no install-time scripts. Its lack of tests, security tooling, and ongoing project activity leaves maintenance and future compatibility uncertain.
42%
Total Score
0
69
75
There has been only one release, published in August 2017, with no releases in the following nine years. This is strong evidence of abandonment risk for a dependency that may need compatibility updates.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with its last push being in August 2017. No provided signal shows compensating maintenance activity.
The artifact includes a README, which is positive for basic consumer guidance, but it has no tests or changelog. The missing tests are a maintenance gap for a library, while the missing changelog is less important for a one-release package.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these values provide no evidence of a wider community capable of sustaining the package.
Composer is used for the build, providing basic packaging structure, but no security-scanning tooling is present. This weakens transparency around ongoing dependency and source risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0 | — | — |
kartik-v/yii2-widget-fileinput Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.