The package has a clear README, a focused set of three runtime dependencies, and a declared license. Its single-maintainer base, absent security policy, and minimal repository activity leave little evidence of ongoing support.
38%
Total Score
25
100
79
50
The latest release was published in March 2016, with no releases in the last 12 months and only two releases overall, indicating severe abandonment risk.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long release gap and leaving current maintenance unverified.
Only one registry account has publish access. This is a thin publishing base for a package with no recent release or commit activity, though access records alone do not establish who actively maintains it.
The repository has only 1 star, 1 fork, and 2 watchers. Popularity is supporting evidence rather than decisive, but these figures provide little evidence of an active user or maintainer community.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities; the package's long inactivity makes this gap more consequential.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0 | — | — |
bower-asset/codemirror Version * | — | — |
bower-asset/tinymce-dist Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.