Clear licensing, release notes, documentation, and package ownership make the release easy to inspect and integrate. The repository is not archived, but recent issue and commit activity is absent, and no security policy is published.
58%
Total Score
67
100
88
50
The package has seven releases over about ten years, but no registry release in roughly five years; this indicates substantially slowed maintenance.
The repository recorded zero commits and zero active maintainers over the last three months, a meaningful sign of stalled development even though it was pushed in 2024.
There were no new or closed issues or pull requests in the last month, while two issues and two pull requests remain open; this supports the picture of limited current maintenance.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The linked repository has no published security policy, reducing clarity about vulnerability reporting and response practices.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kartik-v/yii2-krajee-base Version >=3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.