The MIT license, README, and Composer setup make the package straightforward to inspect and adopt. Pin v2.1 only if you can accept its lack of ongoing maintenance and limited project safeguards.
42%
Total Score
50
100
67
67
The package has only three releases, all concentrated in August–September 2022, and none in the past four years. Its stable version and lack of deprecation reduce adoption risk, but the release history still indicates abandonment risk.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the roughly four-year release gap. The repository is not archived, but there is no recent activity showing ongoing care.
The artifact and repository each contain only six files, including a README, license, Composer manifest, and two source files. This is transparent but provides little supporting project infrastructure for a maintained library.
The repository name matches the package, which supports the link, but its README does not mention the package name. That weakens package-to-repository traceability despite the matching repository identity.
Composer is used as the build tool, which is appropriate for this package, but no security scanning tools are configured. The missing scanning is a modest safeguard gap alongside the broader lack of recent activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.11 | — | — |
sendgrid/sendgrid Version >=5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.