Its BSD-3-Clause license, small dependency set, and matching organization repository make its contents easy to inspect. Nearly eight years without a release or repository activity makes maintenance and compatibility uncertain.
42%
Total Score
50
100
69
75
The package has had only one release, published nearly eight years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap. The repository is not archived, but that does not offset the lack of observed maintenance.
The package contains only README.md, composer.json, and one source file, matching the linked repository. This keeps the release easy to inspect but provides little evidence of broad testing or project maturity.
The package includes a README, while the absence of tests and a changelog is normal for published artifacts and is not treated as a gap here. The short README provides only limited usage guidance.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no additional adoption or community-maintenance signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
npm-asset/bootbox Version ^4.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.