Apache-2.0 licensing, organization backing, and a small dependency surface make the package easy to inspect and adopt. Its missing README and absent security policy reduce transparency alongside the limited maintenance evidence.
38%
Total Score
50
100
81
50
Only one release exists, published in September 2018, with no releases in the following eight years. That is strong evidence of abandonment for a package a developer may need to maintain.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push occurring in September 2018. The long inactivity materially increases maintenance risk.
Composer is used as the build tool, but no security scanning tools are present. The missing scanning reduces repository hygiene evidence without independently making the release unfit.
No repository security policy was found, leaving vulnerability reporting expectations unclear. This is a transparency weakness, though the package's primary risk remains its prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gearsoftware/yii2-core Version @dev | — | — |
gearsoftware/yii2-media Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.