The repository includes tests, a substantial README, a changelog, and clear licensing. No further release or repository commit activity has appeared for about 14 months, while security policy and automated scanning are absent.
58%
Total Score
50
81
75
This is the package's only release, published about 14 months ago, with no releases in the last 12 months. That leaves maintenance continuity unproven and lowers confidence in adopting it.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long gap since the release. This is a meaningful abandonment concern, although the repository is not archived.
Composer is used for builds, but no security scanning tools were detected. The absence of scanning increases maintenance risk for a package with 23 runtime dependencies.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency and maintenance gap for a web application.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mpdf/qrcode Version ^1.2 | — | — |
yiisoft/yii2 Version ~2.0.45 | — | — |
aws/aws-sdk-php Version ^3.169 | — | — |
guzzlehttp/psr7 Version ^1.8 | — | — |
yiisoft/yii2-jui Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.