The package is small but clearly packaged, licensed, documented, and tied to a matching organization repository. Its popularity is limited and the repository lacks a security policy, leaving little evidence of ongoing oversight.
38%
Total Score
63
100
72
88
The last release was over nine years ago, with no releases in the past 12 months. The ten-release history shows prior maintenance but does not offset the prolonged inactivity.
There were no commits and no active maintainers in the past three months, consistent with more than nine years since the last repository push. This is strong evidence of abandonment risk.
There are no open issues or pull requests and no activity in the past month. The clean tracker is mildly positive, but it does not compensate for the broader inactivity.
The repository has only 2 stars, 5 forks, and 3 watchers, indicating limited community adoption and a smaller external signal of support.
Composer is used for builds, but no security scanning tool is configured. The build tooling is appropriate, while the missing scanning is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0 | — | — |
bower-asset/flag-icon-css Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.