The package is licensed, documented, and has a small runtime dependency surface. Its single-maintainer project has had no commits or releases for nearly 11 years, leaving current compatibility and support uncertain.
38%
Total Score
25
100
81
50
Only two releases exist, with the latest published in 2015 and none in the last 12 months; this is strong evidence of abandonment for a framework integration.
There were zero commits and zero active maintainers in the last three months, consistent with the nearly 11-year release gap and indicating substantial abandonment risk.
Only one registry account has publish access. That can be adequate for a small package, but combined with the long period of inactivity it leaves little visible maintenance capacity.
Composer build tooling is present, but no repository security scanning tools were detected; this is a modest transparency and maintenance gap rather than a standalone adoption blocker.
The repository has no published security policy, leaving vulnerability reporting and handling expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.