The README, MIT license, and small Yii2 dependency footprint make the package straightforward to evaluate and integrate. Its single release and complete lack of recent repository activity indicate limited ongoing maintenance, so pinning this version is prudent.
57%
Total Score
50
100
81
50
The source repository is owned by an individual account rather than an organization. That is not inherently unhealthy, but it provides less visible institutional backing for long-term maintenance.
The package has made only one release, on September 17, 2022, and none in the following four years. That strongly limits evidence of ongoing maintenance, though a small stable validator may not need frequent releases.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old last release, this is meaningful evidence of inactivity rather than merely a cosmetic gap.
The repository has zero stars and forks and one watcher, providing little community adoption or external validation. Popularity is supporting evidence only, so this modestly reinforces—but does not determine—the maintenance concern.
Composer is used as the build tool, but no security scanning tool is configured. The missing scanning is a hygiene limitation for transparency, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.