The module has a clear README, a GPL-3.0 license, a matching repository, and organization ownership. Its five runtime dependencies are tightly coupled to the same older stack, while no security policy or scanning is present. Pin this exact version if adoption is unavoidable.
38%
Total Score
50
50
69
83
The package has had only three releases, with the latest in January 2017 and none in the last 12 months despite being over nine years old. This is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with the last repository push occurring in 2017. This materially raises abandonment risk.
The package declares five runtime dependencies, including the tightly coupled blcms-shop and Yii-related modules. This increases compatibility and maintenance exposure for an already old package, though the dependency count is not excessive by itself.
The repository has zero stars and forks and one watcher, providing little community adoption or external validation. Popularity is supporting evidence, so this modestly reinforces the maintenance concern rather than determining it alone.
Composer is used for builds, but no security scanning tools are configured. The missing scanning is a maintenance and transparency gap, although it does not by itself show unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.4 | — | — |
black-lamp/blcms-shop Version * | — | — |
black-lamp/yii2-imagable Version 1.* | — | — |
black-lamp/yii2-multi-lang Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.