The MIT license, stable release line, and matching source tree make adoption straightforward. Six runtime dependencies and no security policy or scanning leave more upkeep and transparency to the consumer.
46%
Total Score
0
50
75
83
The package has 19 releases since July 2017, but none in the last 12 months; its latest release was over two years ago. Earlier regular releases provide some maturity, but the current pause raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. This is strong evidence that maintenance has stopped or become highly intermittent.
The package declares six runtime dependencies, including several Yii extensions, which increases compatibility and maintenance burden for consumers. No development dependencies are declared, so the package provides little visible testing support.
A README is present, but it contains only about 60 characters and offers little integration guidance. The absence of tests and a changelog in the published artifact is normal packaging practice and is not counted against it.
Composer is used for builds, which is appropriate for a Packagist package, but no security scanning tooling is present. That leaves dependency and repository-risk detection to consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0 | — | — |
yiisoft/yii2-jui Version ^2.0.0 | — | — |
yiisoft/yii2-imagine Version * | — | — |
schmunk42/yii2-giiant Version * | — | — |
kartik-v/yii2-widget-typeahead Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.