Tests, release notes, and organization backing improve transparency. The proprietary license and 18 runtime dependencies add practical constraints for adopters.
72%
Total Score
100
50
80
83
Eighteen runtime dependencies create a broad transitive dependency surface for a Yii2 module, increasing upgrade and compatibility burden even though no specific dependency failure is shown.
The manifest declares a proprietary license, so the release is licensed, but the terms may restrict use compared with a conventional open-source license; no license file provides no additional clarity.
The package has 126 releases since February 2017 and a recent release, but only one release in the last 12 months indicates substantially slower current delivery than its historical cadence.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version 2.0.* | — | — |
dmstr/yii2-web Version ^0.3.1 || ^0.4.0 || ^1.0.0 | — | — |
yiisoft/yii2-twig Version ^2.0.4 | — | — |
bedezign/yii2-audit Version ^1.0 | — | — |
kdn/yii2-json-editor Version ^2.5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.