The source has only Composer tooling, with no security policy or automated security scanning. Its single-person ownership and limited repository activity make long-term support less certain.
56%
Total Score
50
100
81
50
One registry account publishes the package. Because the repository is owned by the same individual rather than an organization, this indicates a thin maintainer base and limited continuity.
The latest release was published in April 2019, with no releases in the last 12 months. This is a substantial maintenance concern despite 18 releases during the package's earlier history.
The repository has zero stars and forks and only one watcher. Popularity is not required for health, but these counters provide little supporting evidence of community adoption or shared maintenance.
The repository uses Composer build tooling, but no security-scanning tools were detected. The missing scanning is a modest transparency and hygiene gap for a dependency source.
No security policy was found in the repository. This weakens the project's transparency around vulnerability reporting, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0 | — | — |
cinghie/yii2-fontawesome Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.