The codebase is small, clearly identified, and has a focused dependency profile. Its single release and absence of repository activity since April 2015 leave substantial abandonment risk for a dependency.
42%
Total Score
50
100
78
83
This package has only one release, published more than 11 years ago, with no releases in the last 12 months; that strongly indicates abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and limited maintenance capacity.
There are no open issues or pull requests and no recent issue or pull request activity, offering no evidence of ongoing maintenance or community review.
The repository has zero stars and one fork, providing little evidence of broad community support; this is supporting evidence rather than a verdict by itself.
Composer is used as the build tool, but no security scanning tools are present; the missing scanning is a minor transparency gap, not a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.