The package has a README, a declared license, and no install-time scripts. Its two runtime dependencies keep integration scope small, but the repository provides no tests or security policy.
58%
Total Score
50
100
79
75
The package has 18 releases since December 2015, but none in the last 12 months; its latest release was over two years ago. This indicates materially reduced maintenance activity.
There were no commits and no active maintainers in the three months before collection. Combined with the absence of recent registry releases, this is a meaningful abandonment concern.
Composer is used for builds, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy. That weakens its documented process for handling vulnerabilities and contributor reports.
The assessed release is still version 1.0.0-beta.1, and all recent releases are prereleases. That leaves compatibility and long-term API stability less certain.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.38 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.