The README and three-file artifact make this small behavior straightforward to inspect and use. Its stable MIT release is not deprecated, but the project shows no recent activity or security scanning.
42%
Total Score
75
100
86
50
This is the package's only release, published more than 10 years ago, with no releases in the last 12 months. That strongly increases abandonment risk, although the package is small and stable.
The repository had zero commits and zero active maintainers in the last three months, consistent with a project that has been inactive for many years. The small scope limits the impact somewhat but does not remove the abandonment concern.
Composer is used for the build, but no security-scanning tooling is present. For a small package this is a hygiene gap rather than evidence of an unsafe release, but it reduces transparency around ongoing maintenance.
The repository has no security policy. This is a transparency and maintenance gap, though the package's small three-file codebase limits its practical weight.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.