The single maintainer, one-star repository, and absent security policy provide little evidence of ongoing support. The README and changelog help consumers, but the package still carries substantial abandonment risk.
38%
Total Score
25
100
63
75
This package has had only one release, published in February 2018, with no releases in the last 12 months. That long period without a new release is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's long release gap. This materially lowers confidence in ongoing maintenance.
Only one registry maintainer is listed, leaving the package dependent on a single publisher. The linked repository is user-owned rather than organization-backed, so there is no provided evidence of a broader maintenance bench.
The published artifact includes a README and changelog, which support consumer understanding, while the missing tests are normal packaging practice. The README also explicitly says the module is in development and should be used in production at the consumer's risk.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these very low adoption signals provide little compensating evidence for the maintenance concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
yiisoft/yii2-bootstrap Version ~2.0.0 | — | — |
nikitakls/yii2-editor-md Version * | — | — |
zelenin/yii2-slug-behavior Version ~1.5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.