The package has a clear GPL-2.0 license, repository tests, and a modest dependency set. Its long period without releases or commits leaves compatibility and maintenance risk for new adopters.
42%
Total Score
50
50
81
83
The latest release was published about 8 years ago, with no releases in the last 12 months. Although the package had 26 releases and a prior median interval of about 20 days, the current inactivity is a substantial maintenance concern.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release gap and indicating no visible ongoing maintenance.
The package declares four runtime dependencies, including Yii2 and two project-specific libraries. This is a manageable dependency surface, though the old release age makes compatibility with current dependency versions uncertain.
Composer is used as the build tool, but no security scanning tools were detected. The absence of scanning is a modest hygiene gap, not evidence that the package is unsafe.
No security policy was found in the repository, leaving vulnerability reporting and response expectations undocumented. This adds a transparency concern for a package with no recent maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.4 | — | — |
pastuhov/php-file-stream Version 1.0.* | — | — |
pastuhov/php-exec-command Version 1.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.