The small dependency set and documented package layout make integration straightforward. No security scanning or policy is present, limiting evidence of ongoing project hygiene.
48%
Total Score
25
100
75
83
The package has only one release, published in October 2020, with no releases in the last 12 months. This is strong evidence of abandonment risk for a Yii extension that may need ongoing compatibility work.
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with the old release history, this points to inactive maintenance.
There was no issue or pull-request activity in the last month, with one issue remaining open. This adds modest evidence that the project is not actively maintained.
Composer build tooling is present, but no security scanning tools were detected. That leaves a meaningful project-hygiene gap for a package handling users and access control.
The repository is not archived, which preserves a path for maintenance, but it was last pushed in October 2021 and is therefore substantially stale.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.4 | — | — |
kartik-v/yii2-password Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.