Usable with caveats: the package is licensed, stable, documented, tested, and clearly backed by its matching repository. However, it has had no commits in the last three months, very little community activity, and no documented security process.
68%
Total Score
75
100
83
88
The package has four releases over roughly two weeks, showing an initial period of active delivery, but its short history provides limited long-term evidence.
There were zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern for a package with only about a year of history.
The repository has only 2 stars, 0 forks, and 0 watchers, indicating limited external adoption or review; this is supporting caution rather than evidence that the package is unusable.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-hygiene gap.
The repository has no security policy. For a small UI/date extension this is not severe by itself, but it reduces transparency about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0.49 | — | — |
yiisoft/yii2-bootstrap5 Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.