The repository is correctly linked, licensed, documented, and backed by an organization, with no install-time scripts. Its stable single release has had no updates since January 2022, so pinning it is safer than expecting active support.
57%
Total Score
75
88
75
This package has only one release, published in January 2022, and none in the past 12 months. That long absence of releases is a meaningful maintenance concern.
There were no commits and no active maintainers in the three months measured. Combined with the single-release history, this indicates that active maintenance has stopped or is very limited.
The repository uses Composer for its build process, but no security scanning tool is reported. The missing scanner is a modest transparency gap rather than evidence of unsafe code.
The repository has no security policy. For a small UI extension this is a limited governance gap, but it reduces clarity about how vulnerabilities would be reported.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. All four action references are unpinned, leaving a reproducibility and update-integrity weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.42 | — | — |
kartik-v/yii2-password Version ^1.5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.