The package is small, with a minimal README and no tests or changelog. Its last release and repository update were over six years ago, and the proprietary license limits transparency for adopters.
35%
Total Score
50
100
57
75
The latest release was over six years ago, with no releases in the last 12 months; four releases were published within roughly one day in February 2020. This strongly raises abandonment risk.
The manifest declares a proprietary license, but no license file was detected in the package or repository. That leaves usage and redistribution terms unclear for an open-source dependency.
A README is present, but it is only 30 characters long and the package has no tests or changelog. The GitHub release for this version is a small positive, but it does not offset the limited documentation.
The package and repository are owned by the same individual account, so the source appears aligned with the package. Individual ownership provides limited visible backing for a project that has been inactive for over six years.
There are no open issues or pull requests and no activity in the last month. While a clean tracker can be normal for a small package, it provides no evidence of ongoing maintenance alongside the old last update.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.