The repository has seen no commits in the last three months and was last pushed in November 2016. Its license, README, tests, changelog, and package identity are clear, but the old release line and broad dependency set increase maintenance risk.
35%
Total Score
0
50
64
50
The package has had no releases in the last 12 months, and its latest release was in September 2016 despite being more than 10 years old. This is strong evidence of abandonment for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the last push in 2016, this indicates sustained abandonment risk.
The package declares 25 runtime dependencies, including framework, UI, storage, and image components. That breadth increases maintenance and compatibility exposure for an unrevised release.
Composer is used for builds, which is appropriate for this PHP package, but no security scanning tools are present. This is a hygiene gap rather than evidence that the package is unsafe by itself.
The linked repository is not marked archived, so it remains technically available. However, its last push was in November 2016, which makes this only a limited compensating signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
trntv/probe Version ^0.2 | — | — |
yiisoft/yii2 Version ^2.0.6 | — | — |
symfony/process Version ^3.0 | — | — |
bower-asset/flot Version ^0.8 | — | — |
trntv/cheatsheet Version ^0.1@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.