It has a clear README, MIT licensing, and frequent recent releases. The absence of tests and security scanning leaves less evidence for a production dependency.
67%
Total Score
50
88
75
The repository is owned by a personal GitHub account rather than an organization, so the single-contributor concentration has no visible organizational handoff support.
The package is only 51 days old but has 8 releases, including recent activity, which shows momentum while providing limited long-term maintenance evidence.
One contributor made all 8 recent commits, leaving maintenance dependent on a single person and increasing continuity risk.
The repository recorded 8 commits in the last 3 months, showing active development, but all activity came from one maintainer.
Composer build tooling is present, but no security scanning tools were detected, reducing automated supply-chain and vulnerability oversight.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
yiisoft/yii2-bootstrap5 Version ~2.0.0 | — | — |
besnovatyj/yii2-cms-forms Version ^1.0 | — | — |
besnovatyj/yii2-cms-editor Version ^1.0 | — | — |
besnovatyj/yii2-cms-kernel Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.