The package is clearly licensed, documented enough for its narrow purpose, and has a single runtime dependency. Its simple five-file design limits complexity, but future compatibility fixes and security oversight are uncertain.
42%
Total Score
25
100
71
75
The package has had no release in nearly 10 years: its latest release was in October 2016, with zero releases in the last 12 months. This is strong evidence of abandonment risk despite the small scope.
There were zero commits and zero active maintainers in the last three months, consistent with the repository's last push in October 2016 and materially increasing abandonment risk.
The repository is owned by an individual user rather than an organization, so there is no provided evidence of broader project backing to compensate for the single-publisher and inactive-project profile.
The repository has zero stars and zero forks, with one watcher. Popularity is only supporting evidence, but these counts provide little independent evidence of community validation.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.