The package is clearly documented, licensed, and includes tests. Its broad 15-package runtime dependency set adds upkeep and makes the long period without activity more concerning.
42%
Total Score
0
50
79
75
The latest release was published in May 2021, and there have been no releases in roughly five years. The six releases were initially frequent, but the prolonged halt is a strong abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release hiatus and indicating no current maintenance capacity.
The application declares 15 runtime dependencies, including several project-specific extensions and an OAuth server, creating a substantial maintenance surface for an inactive demo project.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide no community signal to offset the inactivity.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, though it is less serious than the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.14 | — | — |
grigor/yii2-rest Version ^1.0.2 | — | — |
grigor/yii2-signup Version dev-master | — | — |
yiisoft/yii2-imagine Version ^2.3 | — | — |
kartik-v/yii2-editable Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.