Usable with caveats: the release is stable, documented, licensed, and backed by a matching repository. However, the registry has had no new release for about 11 years, and recent repository activity consists of just one contributor and one commit, so long-term maintenance is uncertain.
63%
Total Score
50
100
88
88
The registry namespace and repository are owned by the same individual, which supports package identity, but there is no organization backing shown to provide maintenance redundancy.
The package has five releases, but its latest registry release was about 11 years ago and it has had no releases in the last 12 months. This is a significant maintenance concern, although the repository shows some recent activity.
All recent commits came from one contributor, leaving maintenance dependent on a single active person. The matching repository and package ownership provide identity continuity but do not materially reduce this concentration risk.
The repository recorded only one commit in the last three months from one active maintainer. This recent activity partly offsets the old registry release history but still indicates very limited ongoing maintenance.
Composer build tooling is present, but no security scanning tools are configured. For this small PHP widget this is a transparency gap rather than a severe health risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
symfony/dom-crawler Version * | — | — |
symfony/css-selector Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.