The repository has no security policy or security scanning, while the small dependency set and MIT declaration are positives. A release note and usable README improve transparency, but ongoing support remains uncertain.
42%
Total Score
50
100
72
75
Only two releases were published, both in July 2018, with no release in roughly eight years. This is strong evidence of abandonment risk for a package intended to support an application integration.
The package and repository are owned by the same individual account, providing consistent ownership context but no organizational backing or broader maintenance capacity.
There are no open issues or pull requests and no recent issue or pull-request activity. While this may reflect a small stable project, it provides no evidence of current maintenance alongside the old repository activity.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no evidence of an active user or contributor community.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tooling is present. The missing scanning reduces maintenance transparency for a package that contains application code and database migrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ~3.0.0 | — | — |
yiisoft/yii2 Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.