The package is clearly licensed, has no install-time scripts, and uses a small runtime dependency set. Its repository is backed by an organization, but limited popularity, a thin README, and absent security tooling reduce confidence in long-term support.
58%
Total Score
75
100
75
75
A README is included, but its 600-character content is very thin and provides little usage guidance. Missing tests and a changelog in the published artifact are normal packaging practice and are not concerns here.
The package has 19 releases but none in the last 12 months, and the latest release was published in August 2023, over three years ago at collection time. This indicates meaningful abandonment risk despite its earlier release activity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release and raising maintenance concerns.
The repository has one star, zero forks, and one watcher. Popularity is only supporting evidence, but these very low adoption indicators provide little external evidence of ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected. This is a hygiene gap that modestly lowers transparency and maintenance confidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
bower-asset/croppr Version ^2.3 | — | — |
yiisoft/yii2-imagine Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.