The package has a clear license, a matching repository, and no install-time scripts. Its long period without a release, limited adoption, and absent security policy increase maintenance risk.
55%
Total Score
50
100
69
75
One registry publishing maintainer is consistent with an individually owned project, but it provides little redundancy if that maintainer becomes inactive. The long release gap makes this weakness more relevant.
The package and repository are owned by the same individual account, providing consistent ownership context. There is no organization backing shown to compensate for the single-maintainer model.
The latest release was in June 2022, with no releases in the past four years despite nine releases overall. This is a meaningful maintenance concern, although the repository remains available and is not archived.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a quiet project, but it does not demonstrate active maintenance.
The repository name matches the package name, but the README does not mention the package. The name match reduces concern about a wrong repository, while the missing explicit mention leaves a small transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
denisok94/helper Version * | — | — |
yiisoft/yii2-authclient Version ^2.2 | — | — |
dmstr/yii2-adminlte-asset Version 2.6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.