The MIT license, focused dependency set, clear README, and lack of install-time scripts reduce adoption friction. There is no security policy or scanning, so transparency around handling future issues is limited.
67%
Total Score
50
100
88
75
The package has only two releases across about 22 months, with a median gap of about 21 months; the release in the last 12 months helps, but the cadence gives limited evidence of sustained maintenance.
All one recent commit came from a single contributor, leaving maintenance dependent on one person and creating limited handoff resilience.
One commit from one active maintainer in the last three months shows recent activity, but the volume is too small to demonstrate a strong maintenance cadence.
Composer is used for builds, but no security scanning tools are present, leaving automated detection coverage limited.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
yiisoft/yii2-httpclient Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.