Its matching source repository, MIT declaration, and short README make the package understandable to integrate. The project shows little community or security support, leaving long-term maintenance uncertain.
40%
Total Score
50
64
83
There has been only one release, published about nine years ago, with no releases in the last 12 months. This is strong evidence that the package is no longer actively maintained.
One registry publishing account is a thin maintainer base for a user-owned project. This increases continuity risk, although the matching repository shows the package has a clear owner.
The repository has 1 star, 0 forks, and 1 watcher, providing little evidence of community adoption or external support. Popularity is only supporting evidence, but this reinforces the maintenance concern.
Composer is used as the build tool, which fits the package ecosystem, but no security-scanning tooling is present. The missing scanning is a modest supply-chain hygiene gap rather than proof of unsafe code.
The repository is not archived, which is a useful compensating signal, but it was last pushed about nine years ago and therefore does not offset the stale release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.