It has a clear MIT license, useful documentation, and a small runtime dependency set. Missing security controls and limited project history make long-term support less certain.
65%
Total Score
75
100
83
83
The package published 11 releases over one day and has had no later release across its 114-day observed age, leaving little evidence of an established release cadence.
There were zero commits and zero active maintainers during the last three months. Because the package is only 114 days old, this is a meaningful maintenance concern rather than proof of abandonment.
The repository has zero stars, forks, and watchers, providing no community adoption signal. For a newly published package this is supporting caution, not a decisive health verdict.
Composer is used as a build tool, but no security-scanning tool is present, leaving less automated evidence of dependency and source hygiene.
The repository has no security policy, so users have no documented reporting or response process for vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.51 | — | — |
npm-asset/filepond Version ^4.20 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.