The package is clearly identified, licensed, and documented, with a small dependency set and no install-time scripts. Its source has had no commits or issue activity since April 2020, and it provides no security policy, so maintenance and response capacity are uncertain.
45%
Total Score
33
100
75
88
The package has had no releases in roughly six years, despite 11 releases concentrated in April 2020. This strongly lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers over the last three months, reinforcing the strong abandonment concern indicated by the old release history.
The package and repository are owned by the same individual account, which provides direct ownership alignment but no organization-level backing to compensate for the inactive history.
There have been no new issues or pull requests in the last month and no merged pull requests, consistent with a project that is no longer actively maintained.
Composer is present as a build tool, but no security scanning tools are configured. The missing scanning is a modest transparency gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
symfony/dom-crawler Version * | — | — |
symfony/css-selector Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.