The package includes a license, release notes, a substantial README, repository tests, and static analysis. Recent activity is strong, but all eight recent commits came from one contributor and no security policy is published.
79%
Total Score
67
100
75
The repository is owned by an individual account rather than an organization, so the single-contributor maintenance concentration has no visible organizational handoff buffer.
One contributor made all eight recent commits, creating a meaningful continuity risk for this user-owned project despite the recent activity.
No repository security policy was found. This is a transparency gap for a package that manages feature flags through an administrative UI, though it is not evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/data Version ^2.0 | — | — |
yiisoft/html Version ^3.13 || ^4.0 | — | — |
yiisoft/user Version ^2.0 | — | — |
psr/container Version ^2.0 | — | — |
yiisoft/router Version ^3.1 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.