The package has a clear BSD-3-Clause license, useful documentation, repository tests, and a matching source repository. Its age and lack of recent activity make future fixes and compatibility support uncertain; installation scripts and no security policy add smaller concerns.
52%
Total Score
0
79
50
The repository had zero commits and zero active maintainers in the last three months. Together with the old release history, this indicates a meaningful abandonment risk.
The package defines post-install and post-update Composer scripts. These add installation-time behavior that should be understood before adoption, but the signal alone does not show that the scripts are unsafe.
The latest release was published in February 2020, with no releases in the last 12 months and only three releases overall. This is substantial evidence of aging maintenance, although the stable 1.0.2 release and release notes provide some maturity context.
Composer is used as the build tool, but no security-scanning tools were detected. The build tooling is appropriate for this PHP package, while the missing scanning is a modest hygiene gap.
The repository is not archived, which leaves a path for future maintenance, but its last push was in September 2020. The non-archived status partly compensates for the age but does not demonstrate active support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.