The package is small and clearly scoped, with matching source files, a README, and an MIT license. Its single-maintainer project has been inactive for over a year, so future compatibility fixes may be limited.
60%
Total Score
50
100
88
75
One registry maintainer creates a thin ownership base and increases continuity risk. This is partly consistent with the linked repository being a small user-owned project rather than an organization-backed package.
Only two releases exist, with no releases in the last 12 months and a long median interval between releases. The latest release is recent enough to remain usable, but the slow cadence limits evidence of ongoing maintenance.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with a project that is currently inactive. Its latest push aligns with the latest package release, providing some evidence that the release was maintained at publication time.
Composer is used as a build tool, but no security scanning tool is configured. The absence of scanning is a hygiene gap, not a standalone reason to reject this small package.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This matters for dependency maintenance but is not severe enough to make the release unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.1 | — | — |
npm-asset/nouislider Version ^15.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.