The release is clearly licensed, documented, and tied to a matching source repository with a focused dependency set. However, there have been no releases or commits for more than six years, and the repository has no recent issue or pull-request activity, making future maintenance uncertain.
45%
Total Score
25
100
79
75
The latest release was published on 2 April 2020, with no releases in the last 12 months. This long period without a new release is strong evidence of abandonment risk, although the package has an established release history.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release gap. The repository is not archived, but there is no observed recent maintenance to offset the inactivity.
There were no new or closed issues or pull requests in the last month and no open work. This may reflect a small, stable package, but it provides no evidence of ongoing project responsiveness.
Composer is used as the build tool, but no security-scanning tool is present. The absence is a modest hygiene concern rather than evidence that the release is unsafe on its own.
The repository has no security policy. That is a transparency and vulnerability-reporting gap, though it is secondary to the much stronger evidence from the long maintenance pause.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kartik-v/yii2-krajee-base Version >=2.0 | — | — |
kartik-v/bootstrap-popover-x Version >=1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.