Its small four-file footprint, clear README, MIT license, and two runtime dependencies keep integration straightforward. The project has no tests or security scanning, making future maintenance changes harder to verify.
58%
Total Score
50
100
79
The published artifact includes a README, which supports adoption, while the absence of tests and a changelog is not itself a packaging gap. The linked project also reports no tests, leaving behavior changes harder to verify.
The package has only two releases, with the latest on January 5, 2022, and none in the last 12 months. That long release gap lowers confidence that compatibility or defects are actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with several years since the latest release. The repository is not archived, but there is no recent activity to offset the maintenance concern.
Composer is used for the build, and the package has a simple dependency profile, but the repository reports no security scanning tools. This is a modest transparency and maintenance weakness rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.