Clear documentation, repository tests, and a matching BSD license make the package transparent. Its narrow dependencies and no install scripts limit operational risk, but the lack of security scanning leaves maintenance coverage thinner.
58%
Total Score
50
100
71
75
The package has had no release in nearly six years, with zero releases in the last 12 months. Its five-release history shows a real project, but the long pause raises abandonment risk.
There were no commits and no active maintainers in the last three months, consistent with the much longer release pause. This materially increases the risk that defects or compatibility issues will remain unresolved.
There are four open issues and one open pull request, with no issues or pull requests changed in the last month. The small backlog is not severe, but its lack of movement reinforces the maintenance concern.
Composer build tooling is present, supporting a conventional build, but no security-scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency and maintenance gap, though the package's clear documentation and license provide some compensating evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.14 <2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.