The small codebase has no tests, README, or changelog, and repository security tooling is absent. Its dependencies are explicit and install scripts are absent, but that does not offset the long-standing inactivity.
38%
Total Score
50
100
57
83
The latest release was in November 2016, with no releases in the last 12 months and a package age of over 10 years. This is strong evidence of abandonment risk.
The package has one registry maintainer. Because the linked project is user-owned rather than organization-backed, the narrow publishing and ownership base adds some continuity risk.
The package contains no README, tests, changelog, or release notes. For a small library, the missing consumer documentation and validation artifacts reduce transparency and maintainability.
There has been no issue or pull request activity in the last month, and one issue remains open. This is consistent with a project that is no longer actively maintained.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these figures provide little evidence of a mature user or contributor base.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0 | — | — |
yiisoft/yii2-httpclient Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.