The package has a clear README, tests, changelog, and license, but the repository has no security scanning or security policy. Its small, single-person ownership also leaves little visible maintenance capacity for future fixes.
12%
Total Score
25
100
56
50
Packagist marks the entire package as abandoned, with no replacement identified; this is a direct warning against taking a new dependency on it.
Although the package has 14 releases and a regular historical cadence, its latest release was in May 2017 and it has had no releases in the last 12 months, indicating prolonged abandonment.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since its last update.
The linked repository is archived and was last pushed in December 2017, so active fixes and maintenance should not be expected.
Only one registry account has publish access. The linked repository is user-owned rather than organization-backed, so there is little visible redundancy in publishing or maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
bower-asset/js-cropbox Version ~0.12.0 | — | — |
yiisoft/yii2-bootstrap Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.