The MIT license, focused dependency set, and matching repository make the package easy to inspect. Its tiny audience and lack of security tooling add little reassurance for a dependency that has not changed in years.
38%
Total Score
0
100
69
83
This is the package's only release, published 7 years and 10 months ago, with no releases in the last 12 months. That strongly raises abandonment and compatibility risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and suggesting maintenance has stopped.
The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is not decisive, but this provides little supporting evidence of broad use or community maintenance.
Composer is used for the build, but no security-scanning tools are present. The missing scanning reduces ongoing supply-chain and maintenance assurance.
The repository is not archived, which avoids an explicit abandonment marker, but its last push was 7 years and 10 months ago and does not offset the inactive commit history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.