The focused codebase has a clear README, a declared license, and no install scripts. There is little public activity or security process to support future fixes.
42%
Total Score
50
100
83
83
The registry lists one maintainer, so publishing continuity depends on a single account. The repository is user-owned rather than organization-backed, providing no shown maintainer-base compensation.
The registry namespace and repository owner match, but the owner is an individual user rather than an organization. This supports package identity but does not demonstrate broader project backing.
The package has only one release, published about ten years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a very small project but provides no evidence of ongoing support.
The repository has zero stars and forks and only one watcher, offering little supporting evidence of community visibility or shared maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
stivehu/yii2-enhanced.cookie Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.