The declared BSD license, matching repository, and usable README are positives. Missing security policy and security scanning leave transparency weaker, though they do not offset the maintenance gap.
38%
Total Score
25
75
75
The package has had just one release, published nearly 11 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency.
The repository had zero commits and zero active maintainers in the last 3 months. Combined with the one-release history, this indicates that maintenance has effectively stopped.
There was one open issue and no new or closed issues in the last month. This is consistent with a dormant project, though the small issue count limits how much weight it carries alone.
The repository has no security policy, reducing transparency for a package that handles chat functionality. This is a hygiene gap rather than evidence of a security incident.
Version v0.3 is not a stable major release, which limits maturity evidence, although it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.