The release has a valid MIT declaration, a matching repository, and no install-time scripts. Its single release and seven years without commits, combined with no tests, security policy, or scanning, leave substantial abandonment and maintenance risk.
42%
Total Score
0
50
72
67
There has been only one release, published in March 2019, with no releases in the following seven years. This is strong evidence of an inactive project rather than a maintained dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No provided signal shows compensating maintenance activity.
The package declares five runtime dependencies, including Yii2 and Codeception, which increases the surface area that must remain compatible. No dependency-health evidence is provided to offset that maintenance burden.
The package and repository each contain only three files: .gitignore, README.md, and composer.json. Such a minimal tree provides little implementation or maintenance evidence for a client library.
The package includes a README and has a GitHub release for this version, but the repository has no tests or changelog. The missing tests reduce confidence in ongoing maintenance, while absent tests in the published artifact alone would be normal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version 2.0.16.1 | — | — |
pvsaintpe/yii2-helpers Version * | — | — |
codeception/codeception Version 2.* | — | — |
phpdocumentor/reflection Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.