The repository includes tests, a README, and a small dependency set, but its maintenance capacity is effectively absent. Its declared MIT license and lack of install scripts do not offset the package-level deprecation.
12%
Total Score
0
100
57
88
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because future fixes and compatibility work should not be expected.
The latest release was published in January 2017, and there have been no releases in the last 12 months. That long release gap indicates the package is not being maintained for current consumers.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. This leaves little evidence of ongoing maintenance capacity.
The project uses Composer for builds, but no security scanning tools were detected. This is a minor transparency gap, outweighed by the stronger abandonment and deprecation evidence.
The linked repository is not archived, which avoids an additional hard stop, but its last push was in June 2019 and does not compensate for the package being abandoned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
yiisoft/yii2-gii Version * | — | — |
yiisoft/yii2-bootstrap Version ~2.0.0 | — | — |
bower-asset/typeahead.js Version * | — | — |
bower-asset/typeahead-addresspicker Version dev-typeahead-0.11.1 as 0.1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.