The package has a clear MIT license, a usable README, repository tests, and no install-time scripts. Its small audience and missing security policy add modest uncertainty.
66%
Total Score
50
100
83
75
The latest registry release was in April 2023, with no releases in the last 12 months. Recent repository activity partly offsets the concern, but the absence of published updates still weakens confidence in release maintenance.
One contributor made 100% of the recent commits, leaving maintenance dependent on a single active person; the repository owner is an individual rather than an organization.
The repository recorded one commit in the last 3 months, showing some current maintenance but a very limited pace for a dependency.
The repository has only 5 stars, 1 fork, and 1 watcher. This is supporting evidence of a small user base, not a defect by itself, but it provides little external maintenance signal.
Composer is used as a build tool, which fits the package ecosystem. No security scanning tools are present, leaving a minor process gap but not a severe health issue.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0 | — | — |
npm-asset/dropify Version ~0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.