The small, readable artifact has a clear BSD license, a matching source repository, and no install-time scripts. Its organization backing and simple scope provide limited reassurance, but ongoing maintenance evidence is weak.
43%
Total Score
50
71
75
The package has only one release, published about 8 years and 9 months ago, with no releases in the last 12 months. This is strong evidence of abandonment risk.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package's long release gap and indicating little current maintenance capacity.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these figures provide no external sign of active community use or review.
Composer is used as the build tool, but no security scanning tools are configured. This is a modest transparency and maintenance-hygiene gap, not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This matters for a dependency but is secondary to the much older maintenance record.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.4 | — | — |
bower-asset/bootstrap-social Version ~5.0 | — | — |
powerkernel/yii2-fontawesome Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.