The MIT license, repository tests, changelog, and release notes provide useful transparency. Its focused dependency set and recent release activity support adoption, but maintenance capacity remains narrow.
67%
Total Score
50
100
93
50
Only one registry account has publish access. For this user-owned project that is a genuine continuity concern, although registry access alone does not measure actual contribution activity.
The repository is owned by an individual rather than an organization, so there is no visible organizational maintenance backstop for the concentrated contributor base.
One contributor made all commits in the last three months, so maintenance depends entirely on a single person without visible handoff capacity.
There was one commit from one active maintainer in the last three months. Recent release activity helps, but the low commit volume gives limited evidence of sustained maintenance capacity.
Composer is used for builds, but no security scanning tooling was detected. The absence of scanning is a hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0.35 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.