Its five-file artifact is documented, licensed, and has no install-time scripts. The linked organization repository is not archived, but its zero recent commits and minimal release history leave substantial abandonment risk.
42%
Total Score
50
100
72
83
Only two releases exist, and none were published in the last 12 months; the latest release was over six years ago. This strongly raises abandonment risk despite the package’s stable version.
There were zero commits and zero active maintainers in the last three months, consistent with the release history showing no recent development. This is the strongest evidence of abandonment risk.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little evidence of a broad support community.
Composer is used as a build tool, showing basic project tooling, but no security scanning tools are configured. For a dormant, dependency-bearing package, that is a modest transparency and maintenance gap.
The linked repository is not archived, which means the source remains available. However, its last push was in May 2020, so non-archived status does not demonstrate active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
oyejorge/less.php Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.