A single publisher maintains the package, with no security policy and no repository security scanning. It includes tests, a usable README, and a source repository that clearly matches the package.
67%
Total Score
50
88
75
The package has existed for over five years and reached its latest release recently, but only one release was published in the last 12 months, suggesting modest ongoing activity.
No commits or active maintainers were recorded in the last three months, which weakens evidence of active maintenance despite the recent release.
Composer is used for builds, but no repository security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, making vulnerability reporting and response expectations less clear for consumers.
The single workflow was fully analyzed with no dangerous sinks or audit findings, but both referenced actions are unpinned, leaving builds exposed to moving action revisions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.6 | — | — |
yiisoft/yii2-httpclient Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.