It has a small, understandable artifact, a matching repository, and no install-time scripts. It also lacks a license and security tooling, leaving adoption and maintenance safeguards weak.
32%
Total Score
0
67
100
The package has had only two releases, both in August 2017, with no releases in the last 12 months. This is strong evidence of abandonment for a dependency that may need compatibility or security fixes.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push occurring in August 2017. The long absence of maintenance materially increases adoption risk.
Neither the package nor the repository provides a declared license or license file. That creates a concrete legal and transparency gap for downstream users.
The repository uses Composer, but no security scanning tools are present. This is a modest transparency and maintenance weakness, though the absence of scanning alone is not evidence of a vulnerability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.