The small, tested codebase is licensed and clearly tied to its repository. Its single publisher account, absent security policy and scanning, and minimal repository traction leave little evidence of ongoing support.
42%
Total Score
25
71
50
The package has had no release in nearly eight years, with zero releases in the last 12 months. This is strong evidence of abandonment despite five total releases.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of current maintenance.
Only one account has registry publishing access. The organization-backed repository makes a short registry maintainer list understandable, but it still offers limited evidence of release continuity.
The repository has zero stars and forks and only four watchers. Popularity is supporting evidence rather than decisive, but these figures provide little sign of an active user community.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning reduces maintenance assurance for a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version * | — | — |
yiisoft/yii2 Version >=2.0.4 | — | — |
firephp/firephp-core Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.