The focused file set, matching repository, Apache-2.0 license, and single runtime dependency make the package easy to inspect and integrate. Maintenance evidence is limited, with no release or commit activity for more than six years and no security policy or automated security scanning.
55%
Total Score
50
100
81
83
The registry namespace and repository owner match, and the project is owned by a user account rather than an organization. The matching ownership supports authenticity, while the individual backing offers limited visible maintenance capacity.
The package has 19 releases since 2017, but none in the last 12 months; its latest release was more than six years ago. The historical cadence shows prior maintenance, but the prolonged release gap is a meaningful abandonment concern.
There were zero commits and zero active maintainers in the last three months, following a last push more than six years ago. This is strong evidence that fixes and compatibility updates may not arrive.
Composer build tooling is present, but no security scanning tools were detected. For a small PHP helper this is a modest transparency and maintenance gap, not a standalone severe risk.
The linked repository is not archived, so its source remains administratively active. However, its last push was more than six years ago, consistent with the maintenance concern from the release and commit history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.