yii2 dadata suggestion
39%
Total Score
unhealthy
Risky: no release or repository activity since April 2018.
The package has had only two releases, with the latest published in April 2018 and none in roughly eight years. That long pause is strong evidence of abandonment risk, despite the package not being deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity since April 2018. This substantially lowers confidence in maintenance.
The artifact includes a README and release notes for this version, which provides some consumer and release transparency. However, the README is only 571 characters and its usage example is empty, limiting its practical value.
Composer is used for the build, which fits the package ecosystem, but the repository has no security scanning tools. This is a secondary hygiene gap rather than evidence of malicious behavior.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This adds a transparency concern for a dependency that may receive no active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.