The package is clearly licensed and documented, with only two runtime dependencies and no install-time scripts. Its source repository is minimal, but organization backing and an unarchived repository provide some continuity.
44%
Total Score
75
100
78
75
The last release was about 10 years and 10 months ago, with no releases in the past 12 months and only four releases overall. This is strong evidence of abandonment risk, although the stable 1.1.1 release may still be adequate for a narrow integration.
There were zero commits and zero active maintainers during the last three months, consistent with the last repository push being about 9 years and 9 months ago. This substantially increases abandonment risk.
The repository has 3 stars, 0 forks, and 7 watchers, indicating very limited external adoption or review. Popularity is only supporting evidence, but these numbers provide little community backing for an old package.
The repository uses Composer, which supports reproducible PHP dependency management, but it has no security-scanning tools. The missing scanning is a hygiene gap rather than proof of an unsafe release.
The linked repository is not archived, which is a meaningful positive for continued access. However, its last push was about 9 years and 9 months ago, so availability should not be confused with active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0.6 | — | — |
bower-asset/polyglot Version ^0.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.