The BSD-3-Clause license, focused dependency set, and matching source repository provide useful transparency. Its beta warning, missing security policy, and lack of recent project activity make long-term support unlikely.
35%
Total Score
0
100
75
75
The package has had no releases in roughly 7 years, with zero releases in the last 12 months; its 21-release history does not compensate for the prolonged halt.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the multi-year release gap and indicating serious abandonment risk.
Composer is used as a build tool, but no security-scanning tooling is present. The missing scanning is a modest hygiene gap rather than evidence of abandonment on its own.
The repository has no security policy. This is a transparency and response-process gap, though it is secondary to the stronger evidence of project inactivity.
The assessed version is a prerelease (3.0.1-RC), and the package README identifies the 3.x branch as beta and breaking backward compatibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
bower-asset/materialize Version 1.0.*@RC | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.