The package has had no release or commit activity since January 2019, and its repository has one star with no recent issue or pull-request activity. It is licensed and not deprecated, but the long-term maintenance gap makes adoption risky.
40%
Total Score
25
67
75
The latest release was over 7 years ago, with zero releases in the last 12 months; this is strong evidence of an unmaintained package despite five historical releases.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history and indicating no current maintenance capacity.
The package artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. The missing consumer documentation is a minor integration concern; the absence of repository tests reduces maintenance confidence.
There has been no new or closed issue or pull-request activity in the last month, while one issue remains open; this provides no evidence of active support.
The repository has 1 star, 0 forks, and 0 watchers. Popularity is not decisive, but these very low adoption signals provide little supporting evidence for maturity or sustained maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
npm-asset/cropperjs Version ^1.4 | — | — |
trntv/yii2-file-kit Version @stable | — | — |
yiisoft/yii2-imagine Version ^2.1 | — | — |
npm-asset/jquery-cropper Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.