Repository tests and release notes provide useful support, while the 14 runtime dependencies increase upkeep and the project has no security policy or scanning. The latest release is established, but current maintenance activity is limited.
69%
Total Score
83
50
90
88
Fourteen runtime dependencies create a relatively broad maintenance and compatibility surface for a Yii module. The signal provides no evidence that these dependencies are unsafe, so this is an upkeep concern rather than a severe risk.
The package has existed since April 2015 with 159 releases, but only one release in the last 12 months indicates a slower current cadence. Its long history partly offsets that concern.
There were zero commits and zero active maintainers in the last three months, which is a meaningful sign of limited current maintenance. The recent release and long release history provide partial compensation.
Composer build tooling is present, but no security scanning tools were detected. This modestly reduces maintenance and transparency confidence without making the release unfit to use.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap, not evidence of a vulnerability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
dmstr/yii2-web Version ^1.0.0 | — | — |
bedezign/yii2-audit Version ^1.1 | — | — |
pheme/yii2-settings Version ^0.5.0 || ^0.7.0 | — | — |
dmstr/yii2-json-editor Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.