The package has a clear README, exact-version release notes, and no install-time scripts. Its small, single-owner project and missing security policy provide little visible support if issues arise.
38%
Total Score
33
75
75
The last release was more than eight years ago, with only three releases overall and none in the past 12 months. This is strong evidence of abandonment risk for a dependency.
The repository recorded no commits and no active maintainers in the past three months, consistent with the long release gap and leaving maintenance capacity unproven.
Only one registry account can publish releases. The linked repository is user-owned rather than organization-backed, so there is limited visible redundancy if that maintainer becomes unavailable.
Two issues remain open, with no issues or pull requests closed or merged in the past month. This adds to the lack of evidence that problems are actively handled.
Composer is used for builds, which supports ordinary package management, but no security-scanning tooling is present. This is a modest transparency gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.13 | — | — |
uskur/pdf-label Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.