Risky to adopt: the package has had no release or repository activity for nearly nine years. It is clearly licensed and has source tests and a changelog, but its maintenance appears effectively abandoned.
42%
Total Score
50
64
100
The latest release was published nearly nine years ago, with no releases in the last 12 months. That is a substantial abandonment risk for a library dependency.
There were no commits and no active maintainers in the last three months, consistent with the package having been effectively abandoned.
The repository has only 1 star and 1 fork, providing little supporting evidence of broad review or community resilience. Low popularity is not decisive by itself, but it does not offset the inactivity.
The repository is not marked archived, but its last push was nearly nine years ago, so the non-archived status does not compensate for the prolonged inactivity.
Version 0.0.4 is not a stable major release, which adds compatibility uncertainty; the long period without releases provides no evidence of maturation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.13 | — | — |
overtrue/easy-sms Version ^0.0.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.