It retains an MIT license, tests, and no install-time scripts, but offers little current assurance for new use. The dependency should be avoided unless compatibility work leaves no practical alternative.
8%
Total Score
0
42
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on the package.
The package has 25 releases but none in the last 12 months; its latest release was in November 2018. This indicates prolonged abandonment rather than a merely slow release cadence.
There were no commits and no active maintainers in the last three months, consistent with the archived repository and abandoned registry status.
The linked repository is archived and was last pushed in December 2018, so upstream maintenance and issue resolution should not be expected.
Composer build tooling is present, but no security-scanning tools were detected. That is a modest transparency and maintenance gap, though the abandonment signals carry far more weight.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
nickcv/yii2-encrypter Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.