A clear README, declared BSD-3-Clause license, and small dependency set help adoption. The repository has little visible use, no security policy, and source activity stopped years ago, increasing maintenance risk.
43%
Total Score
100
71
50
The package has had only 3 releases, with none in the last 12 months; its latest release was about 9 years ago. This is strong evidence of stalled maintenance, although the package is not deprecated.
The repository has only 2 stars and 2 forks, providing little evidence of broad community adoption or external maintenance capacity.
Composer is used for the build, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance gap.
The repository is not archived, which avoids the strongest abandonment signal, but it was last pushed about 8 years ago. That long gap still indicates limited ongoing maintenance.
The repository has no security policy. For a web-framework extension, this leaves vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mhndev/yii2-taxonomy-term Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.