Package Health

jc-it/yii2-password-input

The repository is correctly linked, licensed, documented, and backed by an organization, with no install-time scripts. Its stable single release has had no updates since January 2022, so pinning it is safer than expecting active support.

Latest v1.0.0PackagistPackagist

57%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

This package has only one release, published in January 2022, and none in the past 12 months. That long absence of releases is a meaningful maintenance concern.

Repo commit activitycaution

There were no commits and no active maintainers in the three months measured. Combined with the single-release history, this indicates that active maintenance has stopped or is very limited.

Repo toolingcaution

The repository uses Composer for its build process, but no security scanning tool is reported. The missing scanner is a modest transparency gap rather than evidence of unsafe code.

Security policycaution

The repository has no security policy. For a small UI extension this is a limited governance gap, but it reduces clarity about how vulnerabilities would be reported.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. All four action references are unpinned, leaving a reproducibility and update-integrity weakness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Joey Claessen

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/yii2
Version ~2.0.42
kartik-v/yii2-password
Version ^1.5.6

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform