The MIT license, matching repository, and small dependency surface make the code easy to inspect. Organization ownership and GitHub release support help, but they do not offset the lack of ongoing maintenance.
38%
Total Score
25
33
50
The package has only one release, published in February 2015, with no releases in the last 12 months. This is strong evidence that maintenance has stopped.
The repository had zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating substantial abandonment risk.
The artifact has no README, tests, or changelog; missing tests and changelog are normal for published artifacts, but the absent README is a minor integration and transparency gap for a library.
There has been no new or closed issue or pull-request activity in the last month, with one issue still open. This reinforces the lack of current maintenance.
Composer is used for builds, but no security-scanning tooling is present. This is a modest hygiene gap rather than evidence that the package is unsafe by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.