The package is small, clearly licensed, and easy to inspect, with a matching repository and no install scripts. Its single maintainer, absent security tooling, and roughly six years without activity leave little evidence of ongoing support.
43%
Total Score
25
75
75
This is the only release, published in May 2020, with no releases in roughly six years. That long period without updates is strong evidence of abandonment risk, despite the package remaining undeclared as deprecated.
The repository has recorded zero commits and zero active maintainers in the past three months, consistent with the last push occurring in May 2020. The stable 1.0.0 version does not compensate for the lack of any recent maintenance evidence.
Only one registry account has publish access, leaving little visible maintainer capacity if that person stops responding. The repository is user-owned rather than organization-backed, so there is no provided evidence of broader support.
Composer is used for the build, which is appropriate, but no security-scanning tools are present. For a small library this is a transparency and maintenance gap rather than a severe standalone risk.
The repository has no security policy, so users have no documented channel or process for reporting security issues. This matters more alongside the lack of recent maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.