The extension is small and clearly tied to its source repository, with a README covering installation and usage. Its stable release and lack of deprecation help, but the maintenance evidence is too old for a dependable current dependency.
38%
Total Score
50
69
50
There has been only one release, published over 10 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk, despite the package not being formally deprecated.
The registry namespace and repository owner match, and the owner is an individual account rather than an organization. This provides direct ownership alignment but no broader project backing.
The repository had zero commits and zero active maintainers during the last 3 months, consistent with the long period since its last push. This materially increases maintenance and abandonment risk.
The repository has zero stars, forks, and watchers, providing no supporting evidence of adoption or an active user community. Popularity is only supporting evidence, so this reinforces rather than creates the maintenance concern.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tooling is present. This is a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.7 | — | — |
blueimp/jquery-file-upload Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.