The package is small and easy to inspect, with a clear README and no install-time scripts. Its decade without a new release leaves compatibility and maintenance uncertain, while the missing license makes reuse harder to assess.
36%
Total Score
0
64
50
The package has only one release, published over 10 years ago, with no releases in the last 12 months. That strongly suggests the project is no longer actively maintained.
The repository recorded no commits and no active maintainers in the last three months, consistent with the absence of releases and indicating a high abandonment risk.
No license declaration or license file was found in the package or repository. This creates a material transparency and reuse concern for a dependency.
The repository has only 3 stars and no forks, offering little supporting evidence of broad community use or review. Popularity is secondary, but it provides no compensation for the maintenance gap.
The repository uses Composer for its build or packaging workflow, but no security scanning tooling was detected. For this small package, the missing scanning is a minor hygiene gap rather than a decisive risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version 2.0.* | — | — |
bower-asset/angular Version 1.3.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.