There is no security policy or automated security scanning, and the repository has only a small user base. The package is licensed and has a matching source repository, but its maintenance evidence is too weak for a new dependency.
34%
Total Score
50
70
50
The last release was nearly 13 years ago, with no releases in the past 12 months. Twenty-two historical releases show past activity but do not offset the prolonged halt.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap and indicating weak ongoing maintenance.
Composer is used for builds, but no security scanning tools are present. This is a secondary hygiene gap rather than evidence of immediate unfitness.
The repository is not archived, which leaves a path for maintenance, but its last push was nearly 13 years ago and does not compensate for the inactivity shown elsewhere.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package with no recent maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii Version >=1.1.12 | — | — |
sammaye/auditrail2 Version 1.* | — | — |
phundament/p3widgets Version * | — | — |
clevertech/yiibooster Version >=1.0,<3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.