Package Health

glpzzz/yii2-bootstrap

The Twitter Bootstrap extension for the Yii framework (with npm-assets)

Latest 2.1.1PackagistPackagist

43%

Total Score

unhealthy

Risky: maintenance appears abandoned, with no commits or releases since October 2021.

Health Score Breakdown

Release historydanger

The package has had no releases in the last 12 months, and its latest release was published on October 14, 2021. That long release gap is a substantial abandonment concern despite 17 total releases.

Repo commit activitydanger

The repository recorded 0 commits and 0 active maintainers in the last 3 months, matching the prolonged release gap and providing no evidence of current maintenance.

Project backingcaution

The package and repository are owned by the same user account rather than an organization. This does not establish broad project backing and offers limited reassurance against maintainer abandonment.

Repo popularitycaution

The repository has 1 star, 0 forks, and 0 watchers. Popularity is only supporting evidence, but these very low counts provide little external adoption or maintenance reassurance.

Workflow auditcaution

The single workflow was fully analyzed with no failed files, dangerous triggers, injection findings, or high-confidence audit findings. However, all 3 action references are unpinned, leaving a supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Qiang Xue
Alexander Makarov
Antonio Ramirez
Paul Klimov

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/yii2
Version ~2.0.6
—
—
npm-asset/bootstrap
Version ~3.4
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform