The single-maintainer project has no tests or security policy, and its documentation is only a 30-character README. Its MIT declaration and direct repository match help, but this is a poor long-term dependency choice.
38%
Total Score
25
60
50
The package has had no releases in over 9 years: its latest release was June 2017, despite having three releases overall. This is strong evidence of abandonment for a library dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, with its last push in June 2017. This indicates maintenance has effectively stopped.
Only one registry maintainer is listed, and project_backing identifies the repository owner as an individual rather than an organization. That leaves limited visible continuity if the maintainer becomes unavailable.
Composer build tooling is present, but no security-scanning tools are configured. This is a modest hygiene gap that compounds the lack of maintenance evidence.
The linked repository has no security policy, leaving no documented channel or process for handling vulnerabilities. This adds transparency risk for a library containing application and database-related components.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
melkov/yii2-tools Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.