The small contributor base has produced no recent release or repository activity, which raises maintenance risk. The package includes tests, a README, and a stable release, but the license mismatch, unpinned workflow actions, and absent security policy add further concerns.
52%
Total Score
75
79
67
A license file is present in both the artifact and repository, but it is detected as GPL-3.0 while the manifest declares LGPL-3.0-or-later. This mismatch creates a real licensing clarification risk.
The latest release was published in April 2023, and there have been no releases in the last 12 months despite the package being over three years old. Its eight-release history provides some maturity, but the prolonged release gap lowers confidence in ongoing maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with a project whose last push was in April 2023. This is a significant abandonment concern, partly offset by the repository remaining unarchived.
Composer build tooling is present, but no security scanning tools were detected. For a library with no recent activity, the lack of automated security scanning is a modest transparency and maintenance gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.0.0 | — | — |
yiisoft/yii2 Version ^2.0.0 | — | — |
yiisoft/yii2-queue Version ^2.0.0 | — | — |
pozitronik/yii2-traits Version ^1.0.0 | — | — |
pozitronik/yii2-badgewidget Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.