Its MIT license, included tests, and matching source repository support straightforward integration. The small project footprint, absent security policy, and unpinned workflow references leave limited maintenance and build-transparency evidence.
54%
Total Score
25
100
72
75
The package is about 8 years old, with its latest release in May 2018 and no releases in the last 12 months. This is strong evidence of inactive release maintenance, although the stable 1.0.5 version may still be adequate for a narrowly scoped widget.
There were no commits and no active maintainers in the last 3 months, consistent with the repository's last push being about 5 years ago. This materially raises abandonment risk.
The package and repository are owned by the same individual account, so the source ownership is consistent, but there is no organization backing shown to compensate for the thin maintenance base.
The repository has 2 stars, 0 forks, and 1 watcher, indicating a very small adoption and review base. Popularity is only supporting evidence, so this weighs mildly rather than determining the verdict.
Composer is used for builds, but no security scanning tools were detected. For a small PHP widget this is a modest transparency gap rather than a severe defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
bower-asset/lightslider Version ^1.1 | — | — |
bower-asset/lightgallery Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.