Package Health

daxslab/yii2-uploader-behavior

The stable API, clear README, and tiny dependency footprint help integration. However, releases and commits have stopped for about three years, and the license records disagree. The project also lacks a security policy.

Latest 1.0.3PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

A license file is present, but the manifest declares GPL-2.0 while the artifact license file is detected as MIT. This unresolved mismatch creates a real compliance concern.

Release historycaution

The package has only four releases and none in the last 12 months; the latest release was about three years ago. This indicates limited ongoing maintenance, despite a previously regular early cadence.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. Together with the old latest release, this suggests the project may be effectively dormant.

Repo popularitycaution

The repository has three stars, zero forks, and two watchers, indicating a small user and contributor footprint. Popularity is supporting evidence, so this modestly increases maintenance risk but is not decisive.

Repo toolingcaution

The repository uses Composer build tooling, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap rather than evidence of unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Gabriel A. López López

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/yii2
Version *
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform