The package contains a substantial source tree and no install-time scripts, but its consumer documentation is missing. The repository could not be found, leaving maintenance and provenance unverified; pinning this release is risky.
38%
Total Score
100
60
100
The package has only one release, published in October 2018, with no releases in the last 12 months. Nearly eight years without a release is strong evidence of abandonment risk.
The manifest declares a proprietary license, so the release is not unlicensed. However, the proprietary terms may restrict use compared with a typical open-source dependency.
The artifact has no README, which is a meaningful usability gap for a library consumers must integrate. The absence of tests and a changelog is not a concern because those normally belong in the source repository.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.15 | — | — |
yiisoft/queue Version ~2.0.1 | — | — |
yiisoft/swiftmailer Version ~2.0.0 | — | — |
danielstjules/stringy Version ~3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.