The package is clearly licensed and includes a README, changelog, and repository tests. Its small dependency footprint and lack of install-time scripts reduce integration risk, but ongoing maintenance and ownership clarity remain poor.
38%
Total Score
25
100
67
75
The package has had no release in more than 11 years, with zero releases in the last 12 months. That is strong evidence of abandonment for a dependency intended to receive ongoing maintenance.
There were zero commits and zero active maintainers in the last 3 months, consistent with the package having been effectively untouched since 2015.
The repository is owned by an individual user rather than an organization, so there is no visible organizational backing to compensate for the inactive maintainer base.
The repository name does not match the package name and its README does not mention the package. That makes the package-to-repository relationship unclear and weakens source transparency.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no community activity to offset the maintenance concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.