The package is small and focused, with one runtime dependency and clear documentation, tests, a changelog, and an MIT license. Its repository remains available and correctly matched, but security policy and scanning are absent.
55%
Total Score
0
100
72
75
The latest release was June 17, 2020, and there have been no releases in roughly six years. That strongly lowers confidence in ongoing maintenance, although the 31-release history shows the project was previously developed.
There were no commits and no active maintainers in the last three months, consistent with the release history showing prolonged inactivity. This is the main abandonment concern.
The repository has no stars or forks and only two watchers, indicating limited external adoption. Popularity is supporting evidence only, so this modestly reinforces the maintenance concern rather than deciding the score.
Composer build tooling is present, but no security scanning tools are configured. That is a modest supply-chain hygiene gap, not evidence that the package is unsafe.
The linked repository is not archived, which is a positive sign, but its last push was in June 2020 and therefore does not demonstrate current maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.