Licensing and documentation are in place, and the repository clearly belongs to this package. The install hook and 19 runtime dependencies increase maintenance surface, while no security scanning is reported.
35%
Total Score
50
50
71
50
The package has had only two releases, both in December 2016, with no release in more than nine years. This strongly indicates abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no release in more than nine years.
The package declares 19 runtime dependencies, including several project-specific components, creating a broad maintenance and compatibility surface for an otherwise very old release.
A post-install-cmd script runs during installation, adding execution during dependency setup and some supply-chain exposure. The signal does not show that the script is malicious or unsafe.
Composer is used as the build tool, but no security scanning tool is reported. This is a transparency and maintenance gap, though it is less important than the absence of recent development.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.6 | — | — |
yiisoft/yii2-jui Version ~2.0.0 | — | — |
dektrium/yii2-user Version 0.9.* | — | — |
black-lamp/blcms-cart Version 0.1.0 | — | — |
black-lamp/blcms-rbac Version 0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.