The package is small, clearly identified, and has a usable README for integration. Its MIT licensing and simple dependency profile help, but the project shows little evidence of ongoing maintenance or security oversight.
44%
Total Score
50
100
81
75
The latest release was published in October 2019, and there have been no releases in nearly seven years. The four-release history shows an initially active period but no recent maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the last release. No provided signal shows current development activity to offset this.
The repository has zero stars and forks and only one watcher, providing little supporting evidence of community review or shared maintenance. Popularity is only supporting evidence, so this does not determine the result alone.
Composer is used for the build, which is appropriate, but no security-scanning tooling is present. This is a maintenance and oversight gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. The package's small scope limits the impact, but no other provided signal compensates for this transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.