The tiny user base and absent security policy provide little evidence of ongoing support. Its clear license, README, and matching repository improve transparency, but the maintenance record remains a serious adoption concern.
35%
Total Score
0
75
50
The latest release was published in November 2018, with no releases in the past 12 months despite the package being about 8 years and 8 months old at collection time. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the past 3 months, consistent with the lack of releases since November 2018. No newer activity is provided to offset this gap.
The repository has 1 star, 1 fork, and 1 watcher, so there is little visible community adoption to provide maintenance or issue-reporting support. Low popularity alone is not disqualifying, but it reinforces the maintenance concern here.
The repository has no security policy. For a package implementing two-factor authentication, this is a meaningful transparency and vulnerability-reporting gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
authy/php Version 3.0 | — | — |
amnah/yii2-user Version ^5.0 | — | — |
kartik-v/yii2-grid Version @dev | — | — |
borales/yii2-phone-input Version dev-master | — | — |
kartik-v/yii2-krajee-base Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.