The package has a clear MIT license, matching repository, tests, and release notes. Its otherwise solid project structure does not offset the lack of demonstrated ongoing maintenance, so pinning an alternative or maintained fork is preferable.
42%
Total Score
75
100
75
83
The package has had no releases in the last 12 months, and its latest release was in November 2016 after seven total releases. This is strong evidence of abandonment risk despite its earlier release cadence.
There has been no new or closed issue or pull request activity in the last month, with one issue and one pull request still open. This supports the broader indication that maintenance has stopped.
Composer is used as the build tool, but no security scanning tools are present. This is a modest hygiene gap, not a standalone reason to reject the package.
The repository is not archived, which is a compensating sign, but its last push was in November 2016 and aligns with the long release gap. The lack of archival status does not establish active maintenance.
The repository has no security policy. For a small helper library this is a transparency gap, though it is less significant than the long-term maintenance inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.5 | — | — |
yii2mod/collection Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.