The MIT license, matching source repository, and clear README make the small codebase easy to inspect. Its limited validation and missing security policy leave little evidence that future changes will be maintained safely.
42%
Total Score
25
79
75
This is the package's only release, published about five years ago, with no releases in the last 12 months. That leaves no demonstrated release maintenance or evolution.
The repository recorded no commits in the last three months and has no active maintainers in that period; its last push was about four years ago. This strongly supports an abandonment concern.
One issue and one pull request remain open, while neither received activity in the last month. The small counts are not severe alone, but unresolved work reinforces the maintenance concern.
Composer is used for the build, but no security-scanning tooling is present. The build setup is clear, while the missing scanning is a modest hygiene gap.
The linked repository has no security policy. For a small library this is a transparency gap, although it does not by itself show unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.43 | — | — |
spaf/simputils Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.