Package Health

cza/yii2-base

Its MIT license and changelog improve transparency. The broad dependency set and absent security policy add maintenance overhead.

Latest 1.35PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has had no release in nearly six years, despite 38 releases historically. This is strong evidence of abandonment risk for a dependency that may need compatibility or security updates.

Repo commit activitydanger

There were no commits and no active maintainers in the last three months, consistent with the nearly six-year release gap and increasing abandonment risk.

Dependency profilecaution

Twenty-nine runtime dependencies create substantial compatibility and transitive-maintenance exposure for a Yii2 utility package, with no development dependencies shown to support the source project.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, so the source association is not clearly demonstrated and may reflect a package-repository mismatch.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these values provide little evidence of community support.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ben Bi

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/yii2
Version 2.*
—
—
yiisoft/yii2-jui
Version *
—
—
kartik-v/yii2-grid
Version *
—
—
kartik-v/yii2-mpdf
Version *
—
—
kartik-v/yii2-dialog
Version *
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform