The package has no recent maintenance or active repository work, and its source project is archived. MIT licensing and a small, clear dependency set do not offset the abandonment risk; choose a maintained replacement.
12%
Total Score
33
100
50
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because the registry itself no longer presents it as maintained.
The latest release was in November 2018, and there were zero releases in the last 12 months despite the package being about 8 years old. This indicates prolonged release inactivity.
The repository recorded zero commits and zero active maintainers in the last 3 months. This confirms that the lack of releases reflects inactivity rather than merely a stable release cadence.
The linked repository is archived, with its last push in November 2018. An archived source project is a strong indicator that future fixes and support are unlikely.
The repository owner is an organization, which provides some ownership context and makes the single registry maintainer unsurprising. That backing does not offset the repository's archived status.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.