The small project has a clear README, release notes, matching source repository, and organization backing. Its sparse release and commit history limits confidence in ongoing maintenance, so pinning an older known-good version may be preferable.
42%
Total Score
75
100
81
75
Packagist marks the entire package as abandoned and provides no distinct replacement, which is a serious warning for a new dependency despite the repository remaining available.
Only 3 releases have appeared since April 2017, with no releases in the last 12 months; the latest release is recent enough to show some activity but the overall cadence is sparse.
There were no commits and no active maintainers in the last 3 months, which weakens evidence of continuing maintenance even though the repository was recently pushed for the assessed release.
The repository has no published security policy, leaving reporting and response expectations unclear; this is a minor transparency gap rather than a standalone adoption blocker.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.