Package Health

liv/yii2-file-kit

Documentation and tests make integration clearer, and the source tree matches the package. The lack of activity leaves maintenance and compatibility concerns for a production dependency.

Latest 1.2.0PackagistPackagist

40%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The latest release was published in July 2015, and there have been no releases in roughly 11 years. This is strong evidence of abandonment for a maintained library.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last three months, consistent with the package's roughly 11-year release silence.

Dependency profilecaution

The package declares nine runtime dependencies for its upload, storage, and UI features. This is a meaningful dependency surface for an unmaintained package, though the count alone is not severe.

Project backingcaution

The source repository is owned by an individual rather than an organization. This does not prove abandonment, but it provides limited backing to offset the long period without activity.

Repo toolingcaution

Composer build tooling is present, but no security scanning tooling was detected. That weakens ongoing transparency, especially alongside the repository's prolonged inactivity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Eugene Terentev
Liv

Direct Dependencies

DependencyLast ReleaseScore
league/url
Version ~3.0
—
—
yiisoft/yii2
Version ~2.0.0
—
—
league/flysystem
Version ~1.0
—
—
yiisoft/yii2-jui
Version ~2.0.0
—
—
bower-asset/jcrop
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
11 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform