The package has a clear README, release notes, and a matching repository, with no install-time scripts. Its MIT declaration conflicts with the Apache-2.0 license detected in the artifact, and the source shows no recent work.
43%
Total Score
0
70
75
The package has had no release in more than 8 years: its latest release was June 11, 2018, despite 12 earlier releases. This is strong evidence of abandonment for a framework dependency.
The repository recorded 0 commits and 0 active maintainers in the past 3 months, consistent with the long release gap. The repository is not archived, but there is no observed recent maintenance.
The manifest declares MIT and the artifact includes a license file, but the detected license is Apache-2.0, creating a material licensing inconsistency despite the presence of license files.
The linked repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, especially for a framework with backend and administrative components.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.