Its MIT licensing, clear README, and matching repository provide useful transparency. The tiny project footprint and absent security policy leave less evidence of ongoing care.
60%
Total Score
50
100
83
75
The package and repository are owned by the same individual account, so there is no organizational backing shown to compensate for the single-maintainer footprint.
The package has only 3 releases since July 2019, with no releases in the last 12 months and the latest published over 2 years ago. This indicates slow maintenance, though the stable 2.1.0 release remains available.
The repository had 0 commits and 0 active maintainers in the last 3 months, consistent with the release gap and providing little evidence of current maintenance.
The repository has 1 star and 1 fork, indicating a very small user and contributor footprint. Popularity is only supporting evidence, but this offers little external validation or resilience.
The repository has no security policy, reducing transparency about how vulnerability reports would be handled. This is a hygiene gap rather than evidence of an active security problem.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
npm-asset/sweetalert2 Version 11.7.3 | — | — |
yiisoft/yii2-bootstrap5 Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.