The README, release notes, and long release history make the package reasonably transparent. Its tiny repository has no tests or security scanning, and recent commit activity is absent, so maintenance capacity is the main concern.
67%
Total Score
50
100
94
88
The repository recorded zero commits and zero active maintainers in the last 3 months. A recent release partly offsets this, but the lack of development activity weakens confidence in ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected. For an authentication-related extension, that is a meaningful hygiene gap, though not evidence of an unsafe release by itself.
The repository has no security policy. This reduces transparency for reporting issues in an authentication component, but does not by itself show abandonment or a vulnerable implementation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.