The package is small and clearly structured, with tests, a README, and no install-time scripts. Its last release and repository activity were nearly 12 years ago, while the repository does not explicitly identify the package and its license metadata conflicts.
40%
Total Score
33
100
56
83
Only two releases were published, both in October 2014, with no releases in the last 12 months; this is strong evidence of abandonment for a dependency.
There were no commits and no active maintainers in the last three months, consistent with the long release gap and indicating severe maintenance risk.
A license file is present, but the manifest declares BSD-3-Clause while the artifact license file is recognized as MIT. The package is licensed, yet the conflicting metadata reduces transparency.
The repository is owned by an individual account rather than an organization, providing no visible organizational backing to compensate for the lack of recent activity.
There were no new or closed issues or pull requests recently. With no recent commits or releases, this looks inactive rather than efficiently maintained.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii Version ~1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.