The package has a matching organization repository, an MIT license file, and a usable README. Its deployment scripts and broad dependency set increase maintenance burden, while security tooling is absent.
43%
Total Score
50
50
79
50
The package has 73 releases since June 2020, but none in the last two years; the latest release was in May 2024. That prolonged release gap is strong evidence of abandonment risk despite its previously regular cadence.
The repository recorded zero commits and zero active maintainers in the last three months, corroborating the release gap and indicating no current maintenance capacity.
The package declares 25 runtime dependencies, including framework, messaging, database-extension, and frontend components. This broad dependency surface raises upgrade and maintenance burden for an already inactive project.
The package runs post-install and post-update Composer scripts, increasing installation complexity and the amount of package code executed during dependency operations.
Composer is used for builds, but the repository reports no security scanning tools, leaving an important maintenance and vulnerability-detection gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/zmq Version ~0.3 | — | — |
yiisoft/yii2 Version ^2.0.39.3 | — | — |
monolog/monolog Version ^1.2.5|^2.7 | — | — |
yiisoft/yii2-gii Version ~2.0.0 | — | — |
npm-asset/i18next Version ~19.8.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.