The package has a clear README, a changelog, a stable release line, and a small runtime dependency set. Its repository is still present and matches the package, but the long period without maintenance makes future compatibility uncertain.
58%
Total Score
50
100
86
75
The package and repository are owned by the same individual account rather than an organization, so the single-person ownership context offers limited backing capacity.
The package has 16 releases since March 2015, but none in the last 12 months and its latest release was in August 2021—about five years ago.
Composer is used for build and package management, but no repository security-scanning tool is present. This is a modest transparency and hygiene gap, not evidence of abandonment by itself.
The repository has no security policy. That limits vulnerability-reporting transparency, though it is less significant than the observed maintenance slowdown.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.13 | — | — |
bower-asset/js-cookie Version ~2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.