The repository has had no commits from any active maintainer in the last three months, and all five workflow actions are unpinned. A recent release, clear licensing, tests in the repository, and a matching source project provide useful support, but ongoing maintenance remains uncertain.
62%
Total Score
67
100
94
83
The repository recorded zero commits and zero active maintainers during the last three months. The recent release and push show some current activity, but the short-term development pause raises maintenance concerns.
There are only three open issues and no open pull requests, but there was no issue or pull-request activity in the last month, offering limited evidence of active support.
Composer build tooling is present, but no security scanning tool was detected, leaving repository security hygiene less demonstrable.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
Both workflows omit a top-level permissions block, which is acceptable on its own, but all five analyzed action references are unpinned, weakening reproducibility and allowing referenced action code to change over time. The audit completed fully and found no trigger or injection issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version 2.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.