Package Health

bugban/yii2

The small codebase has clear installation guidance and recent activity from two contributors. No tests, security policy, or security scanning reduce confidence in its long-term safeguards, while the package has little adoption evidence so far.

Latest v1.7.2PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Project backingcaution

The repository is owned by an individual user rather than an organization, so the project does not show organizational maintenance backing. Recent activity from two contributors partly offsets that limitation.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This is weak adoption evidence, but popularity is supporting context rather than a health verdict for a young, focused package.

Repo toolingcaution

The repository uses Composer, appropriate for this PHP package, but no security scanning tools were detected. The missing scanning reduces assurance for supply-chain hygiene.

Security policycaution

The repository has no security policy. That leaves vulnerability-reporting and response expectations unclear, a real transparency gap for an error-monitoring integration.

Workflow auditcaution

No GitHub Actions workflows were present, so there were no workflow triggers, permissions, or unpinned actions to audit. This avoids workflow risk but provides no CI evidence for tests or release checks.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/yii2
Version >=2.0
—
—
bugban/php-sdk
Version ^1.7.2
—
—

Weekly Downloads

Info

Last Published
8 hours ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform