The license metadata conflicts with the GPL-3.0 license file, and the manifest lists the package itself as a runtime dependency. Documentation and repository tests provide some support, but the maintenance and licensing concerns remain substantial.
38%
Total Score
0
50
63
50
The latest release was published in June 2018, and there have been no releases in the last 12 months. This long release gap is strong evidence of abandonment for a package used in application authorization.
The repository recorded zero commits and zero active maintainers in the last 3 months, matching the long release gap and providing no evidence of current maintenance.
The package declares clement/yii-rest-rbac itself as a runtime dependency, which is an unusual and potentially erroneous dependency graph entry. The other runtime dependency count is small, but it does not explain this self-reference.
The manifest declares MIT, but the artifact license file is recognized as GPL-3.0. Although a license file exists, the mismatch creates a material legal uncertainty for adopters.
The linked repository has no security policy. This is a transparency and maintenance gap for a package handling authentication and role-based access control, though it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ~3.2.0 | — | — |
yiisoft/yii2 Version ~2.0.7 | — | — |
clement/yii-rest-rbac Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.