The small artifact is clearly identified and carries an MIT license. Maintenance has been quiet since February 2022, with no recent repository activity and no security policy or scanning.
60%
Total Score
50
63
50
The package has four releases since February 2018, but none in the last four years; the latest release was in February 2022. This materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but current maintenance is not evident.
There were no new or closed issues or pull requests in the last month, and no open work is visible. For this small package that is not independently severe, but it provides no evidence of ongoing support.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these numbers offer little external evidence of maturity or community support.
Composer is used for the build, which is appropriate, but no security scanning tools are configured. This is a maintenance and transparency gap rather than a release-blocking risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.6 | — | — |
bower-asset/jquery.scrollbar Version ^0.2.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.