The project is licensed and matches its repository, but it has little supporting maintenance evidence. Its three-file artifact has no tests, and the repository has no security policy, making changes harder to validate.
38%
Total Score
50
100
78
67
Only one registry maintainer is listed. For an individually owned package this is unsurprising, but it leaves limited apparent continuity if that maintainer stops supporting it.
The artifact contains only three files, including the implementation, README, and Composer manifest. This may suit a very small widget, but it offers little evidence of testing or broader project maturity.
A README and GitHub release provide basic consumer documentation, but the package has no tests and no changelog; the missing tests reduce confidence in future changes.
The repository is owned by an individual rather than an organization, which is consistent with the single-maintainer package but offers limited demonstrated backing.
The package has had only one release, with no releases in about 10 years. That strongly raises abandonment and compatibility risk for a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.