The project is small and clearly documented, with a matching repository, MIT licensing, and no install-time scripts. Its only release was published about 10 years ago, with no recent commits and no security policy, making abandonment the main concern.
48%
Total Score
67
100
78
83
Only one account has registry publishing access. The repository is also owned by that individual, so this is consistent ownership rather than evidence of a missing organization, but it leaves little visible maintainer redundancy.
The package has only one release, published about 10 years ago, with no releases in the last 12 months. That is strong evidence of inactivity, although the package's small scope may reduce the need for frequent releases.
There were no commits and no active maintainers in the last three months, consistent with a project that has been inactive for about 10 years. This materially raises abandonment risk.
The repository has one star, one watcher, and no forks, indicating very limited community visibility and little independent maintenance support. Low popularity is supporting evidence rather than a verdict by itself.
Composer is used for project tooling, which fits the package ecosystem, but no security-scanning tools are configured. For a small, long-inactive package this leaves a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version 2.0.* | — | — |
bower-asset/velocity Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.