The BSD-3-Clause license, clear README, and matching repository make adoption straightforward. Low repository visibility and no security policy provide limited support evidence, so pin this version.
62%
Total Score
100
100
83
75
The package has 23 releases since June 2014, but none in the last 12 months and the latest release was in November 2023. This is meaningful evidence of slowing maintenance for a library dependency.
The repository has zero stars and forks and only two watchers, so there is little visible community evidence to support long-term maintenance. Popularity is supporting evidence, so this is a mild concern rather than a decisive risk.
The project uses Composer, which fits the package ecosystem, but no security-scanning tooling was detected. This leaves a modest transparency and maintenance gap.
The repository has no security policy, making vulnerability reporting and disclosure expectations less clear for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kartik-v/yii2-krajee-base Version >=1.9 | — | — |
kartik-v/php-date-formatter Version >1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.