The license, README, package contents, and repository identity are all in place. However, no release has appeared for more than six years, and the repository has had no recent commits or issue activity, making future fixes uncertain.
42%
Total Score
25
71
75
The package has 51 releases but none in the last 12 months; its latest release was more than six years ago. This is strong evidence of abandonment risk for a dependency that may need fixes.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap. No provided signal shows compensating recent maintenance.
There were no new issues, closed issues, new pull requests, or merged pull requests in the last month. This supports the conclusion that the project is inactive, although no open-issue count was available.
The repository has zero stars, forks, and watchers, providing no community activity to supplement the single-user project backing. Popularity is supporting evidence only, but here it offers no compensating signal.
Composer is used for the build, but no security scanning tool was detected. The missing scanning is a maintenance and transparency gap, though it is secondary to the project's inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kartik-v/yii2-dialog Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.