The package is small and clearly identified, with a stable version, README, release notes, and one runtime dependency. Its missing security policy, single maintainer, and long period without releases or commits leave little evidence of ongoing support.
43%
Total Score
25
100
75
83
Only two releases were published, with the latest about eight years ago and none in the past 12 months. This strongly indicates abandonment risk despite the package not being deprecated.
The repository recorded no commits and no active maintainers in the past three months, consistent with the long release gap and limited evidence of ongoing maintenance.
One registry publishing maintainer provides a thin support base for a user-owned project, increasing continuity risk if that person becomes unavailable.
The repository has one star and four forks, providing little supporting evidence of broad community review or shared maintenance. Popularity is only supporting evidence, so this does not determine the score by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is less severe than the lack of maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.