The MIT license, matching repository, and usable README provide basic transparency. Its three runtime dependencies and lack of security tooling add little assurance, while the project has no meaningful maintenance evidence.
12%
Total Score
25
50
63
75
Packagist marks the entire package as abandoned, with no replacement named. This is a severe adoption risk for a dependency whose future maintenance is not supported.
The latest release was in January 2016, and there were no releases in the last 12 months; the package has been without a release for about 10 years. This strongly indicates abandonment.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No provided maintenance signal compensates for this inactivity.
The package declares three runtime dependencies and no development dependencies. This is a manageable dependency surface, but it offers no evidence of ongoing compatibility maintenance.
The package and repository are tied to the same individual account rather than an organization. This is not inherently unhealthy, but it provides limited evidence of maintained project backing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
dektrium/yii2-user Version ^0 | — | — |
mdmsoft/yii2-admin Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.