The package is clearly documented and licensed, with a focused dependency set and no install-time scripts. Its maintenance record is the main concern, with no release or commit activity for nearly seven years and no security scanning or policy.
45%
Total Score
0
100
71
75
The latest release was published in September 2019, and there have been no releases in the last 12 months. The short early release interval shows initial activity but does not offset the nearly seven-year release gap.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating a substantial abandonment risk.
The repository has zero stars and forks and one watcher, showing little visible adoption or community support. Popularity is supporting evidence only, but here it provides no compensating maintenance signal.
Composer is used as the build tool, but the repository has no security scanning tools. This is a minor transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This adds a modest transparency concern, especially alongside the inactive maintenance record.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
samdark/sitemap Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.