Its MIT licensing, clear README, and release notes support transparent use. However, there has been no release or repository activity for about 8 years, while security scanning and a security policy are absent.
42%
Total Score
25
71
83
The latest release was published about 8 years ago, with no releases in the last 12 months; the earlier cadence does not compensate for this prolonged inactivity.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with long-term abandonment risk.
There were no new or closed issues or pull requests in the last month, and four issues remain open, providing no evidence of current maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving maintenance and supply-chain checks weaker than they could be.
The linked repository is not marked archived, although its last push was about 8 years ago and the activity signal shows that practical maintenance has stopped.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.9 | — | — |
yiisoft/yii2-jui Version >=2.0.6 | — | — |
npm-asset/fullcalendar Version v3.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.