The package has a valid BSD-3-Clause declaration, a matching repository, and no install-time scripts. Its documentation is brief, and the project has no security policy or security-scanning tooling.
38%
Total Score
50
100
57
75
The package is over 7 years old but has had no release in more than 7 years; all four releases arrived within roughly 1 hour, indicating sustained abandonment risk.
Only one registry publisher account is listed. A single maintainer is not inherently unsafe, but with no recent releases or repository activity it increases continuity risk.
A README is included, and the absence of tests or a changelog in the package is normal packaging practice. The 452-character README provides only minimal usage guidance.
There are no open issues or pull requests and no activity in the last month; combined with the old last push, this supports a picture of an inactive project rather than a healthy quiet release.
The repository has 1 star, 0 forks, and 1 watcher. Low adoption is supporting evidence rather than a verdict, but it provides little evidence of a broader maintenance community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.