The package is compact and clearly documented, with a matching source repository and no install-time scripts. Its MIT licensing and small dependency set make review straightforward, but the missing security policy and scanning leave less assurance around ongoing maintenance.
53%
Total Score
0
100
71
75
The latest release was published on November 6, 2017, and there have been no releases in roughly 8 years and 10 months. The package had three releases over its lifetime, so this is a substantial maintenance concern.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap. The repository is not archived, but there is no observed recent maintenance activity.
The repository has zero stars and forks and one watcher, providing little community evidence to compensate for the absence of recent releases or commits. Popularity is supporting evidence rather than a standalone verdict.
Composer is used for builds, but no security scanning tools are configured. This is a modest transparency and maintenance gap, though it does not by itself make the release unfit.
The repository has no security policy, leaving no documented path for reporting vulnerabilities. This weakens project transparency but is less severe than the observed maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2 | — | — |
npm-asset/persian-datepicker Version 1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.