The package is documented enough to integrate, with a changelog and a focused dependency set. Its small, inactive project has limited evidence of ongoing support, and the licensing terms may block normal open-source use.
38%
Total Score
33
100
69
50
The package has had no release in more than 7 years, with zero releases in the last 12 months. Its five historical releases show it was once maintained, but that does not offset the prolonged inactivity.
There were zero commits and zero active maintainers in the last 3 months. Combined with the last push in June 2019, this is strong evidence of abandonment risk.
The manifest declares a proprietary license, and no license file was detected in either the package or repository. Although this is a license declaration rather than an unknown state, it may prevent normal open-source use and redistribution.
Only one registry account can publish the package, leaving a thin publishing base. The repository is user-owned rather than organization-backed, so no compensating organizational capacity is shown.
The repository is owned by the same individual account as the registry package, and the owner type is User. This supports package identity but provides no organizational backing to offset the single-maintainer risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
yiisoft/yii2-imagine Version * | — | — |
kartik-v/yii2-widgets Version * | — | — |
mongosoft/yii2-upload-behavior Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.