It is licensed, documented, and its repository clearly matches the package. Its 19 runtime dependencies and lack of security scanning add maintenance burden for a bundle that has seen little recent care.
43%
Total Score
25
50
81
50
The latest release was published in October 2018, with no releases in the following nearly eight years. That is strong evidence of abandonment despite the package's earlier release history.
The repository shows no commits and no active maintainers in the measured three-month period, while its last push was in September 2019. This confirms that maintenance has effectively stopped.
The package brings in 19 runtime widget dependencies, creating a broad dependency surface that may require coordinated updates. The bundle's documented purpose explains the count but does not remove the maintenance burden.
There were no new or closed issues and no pull-request activity in the measured month, with 59 issues still open. This supports the broader evidence of an inactive project.
Composer build tooling is present, but no security-scanning tools were detected. That is a transparency and maintenance gap, though it is secondary to the long period without updates.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kartik-v/yii2-krajee-base Version * | — | — |
kartik-v/yii2-widget-affix Version * | — | — |
kartik-v/yii2-widget-alert Version * | — | — |
kartik-v/yii2-widget-growl Version * | — | — |
kartik-v/yii2-widget-rating Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.