The small codebase has a clear README, a license, and no install-time scripts. A single maintainer and no security policy or automated security scanning add maintenance and transparency concerns.
42%
Total Score
25
71
75
The package has only one release, published over 11 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency that may need fixes or compatibility updates.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, with its last push in 2015. The absence of recent development materially raises maintenance risk.
The artifact declares GPL-3.0+ and includes a GPL-3.0 license file, so the release is licensed; the detected license is narrower than the declaration and should be checked for intended redistribution terms.
Only one registry maintainer is listed. The matching user-owned repository and absent recent commit activity provide no evidence of a broader active maintainer base.
Composer build tooling is present, but no security scanning tools are configured. This is a modest repository hygiene gap, especially alongside the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version 2.0.* | — | — |
bower-asset/jquery-slimscroll Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.