The package is clearly licensed, documented, and has a small dependency surface. Its lack of tests and security tooling adds maintenance uncertainty, while the long period without updates is the main concern.
35%
Total Score
0
100
58
83
Only one release exists, published in December 2015, with no releases in the last 12 months. Nearly eleven years without a new release is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap and limited evidence of ongoing maintenance.
The artifact includes a substantial README and changelog, and the repository has a changelog, but neither the package nor repository has tests. The documentation helps transparency, while the missing tests reduce confidence in maintenance quality.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence that the release is unsafe.
The linked repository is not archived, which is a positive sign, although its last push was in December 2015 and does not offset the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.