The package is well documented, licensed, tested, and has only three runtime dependencies. Its source was last pushed in February 2019, with no commits in the past three months and no security policy or scanning.
40%
Total Score
50
71
75
Only two releases exist, with the latest published in April 2017 and none in the last nine years. This is strong evidence of abandonment for a package still being considered as a new dependency.
There were no commits and no active maintainers in the past three months. Combined with the last repository push in 2019, this indicates that maintenance has effectively stopped.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and maintenance gap, though it is less serious than the lack of recent development.
The repository has no security policy, leaving no documented route for reporting vulnerabilities. This is a modest transparency gap for a package intended to be used in applications.
Version 0.1.0 is not a stable major release, so its API maturity is limited. The release is not marked as a prerelease, which provides a small compensating signal but does not offset the early version.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hiqdev/yii2-menus Version <2.0 || dev-master | — | — |
yiisoft/yii2-bootstrap Version ~2.0.0 | — | — |
hiqdev/yii2-thememanager Version <2.0 || dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.