Its declared BSD-3-Clause license and package README help transparency, but there are no tests, no security policy, and no security scanning. The package remains unarchived and correctly linked to its repository, yet maintenance evidence is extremely old.
32%
Total Score
64
75
The latest release was in November 2015, with no releases in the last 12 months and a package age of about 11 years. This is strong evidence of abandonment for a user-management library.
The package includes a substantial README and this release has a GitHub release, but it has no tests and no changelog; the missing tests reduce confidence in ongoing maintenance and regression safety.
Composer build tooling is present, but no security scanning tools are reported. That leaves security hygiene weaker than expected for an authentication and permissions module.
The repository is not marked archived, which is a small positive, but it was last pushed in November 2015 and therefore shows no recent maintenance.
The linked repository has no security policy, leaving no stated process for reporting or handling vulnerabilities in a package that manages accounts, passwords, and authorization.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
kuzmiand/yii2-cropper Version * | — | — |
yiisoft/yii2-authclient Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.