Handy, light user extension with oauth and classical email login
10%
Total Score
critical
Unfit to use: the package is marked abandoned.
The registry marks the entire package as abandoned, with no replacement package specified. This is a severe adoption risk because the package is explicitly withdrawn from active use.
Only one release exists, published about 4 years and 7 months ago, with no releases in the last 12 months. This provides strong evidence of abandonment and no ongoing maintenance.
The package declares seven runtime dependencies and no development dependencies. That dependency surface increases integration and maintenance exposure for a small extension, although the signal does not show those dependencies are themselves unhealthy.
Only one account has publishing access. This indicates limited release resilience if fixes or ownership changes are needed, though registry access alone does not prove whether other contributors exist.
Version 0.1.0 is not a stable major release, which offers limited maturity evidence. The fact that it is not prerelease is a small compensating point, but not enough to offset the package's age.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.14 | — | — |
yiisoft/yii2-authclient Version ~2.1.0 | — | — |
yiisoft/yii2-bootstrap4 Version ~2.0.0 | — | — |
rmrevin/yii2-fontawesome Version 2.10.* | — | — |
achertovsky/yii2-handy-helpers Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.