The MIT license, readable documentation, and focused dependency set make integration straightforward. No security scanning or policy is visible, adding transparency concerns.
48%
Total Score
25
100
75
83
The package has had no releases in the last 12 months, and its latest release was published in August 2019, about 7 years ago. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long gap since the last release and increasing abandonment risk.
The repository is owned by an individual account rather than an organization. This is not inherently unhealthy, but it offers less visible institutional backing for a project already showing prolonged inactivity.
Composer is used for builds, but no security scanning tools are configured. The missing scanning coverage is a modest transparency and maintenance concern.
The linked repository is not archived, but its last push was in August 2019, so the unarchived status does not compensate for the lack of recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
monolog/monolog Version ^1.20 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.