The package is small and clearly matches its repository, with a simple Yii2 dependency and an MIT declaration. Brief documentation, no security policy, and no security scanning limit transparency for future maintenance.
52%
Total Score
50
100
79
50
The package has 69 releases, but its latest release was in October 2021 and it has had no releases in the last 12 months. This long period without published updates raises maintenance risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the package's multi-year release pause. The repository is not archived, but current maintenance capacity is not evident.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little evidence of an active user or contributor community.
Composer is used for the project, which supports reproducible package management, but no security scanning tools were detected. That leaves a meaningful supply-chain hygiene gap for a package with no recent maintenance activity.
No repository security policy was found. This is a transparency gap because consumers have no documented channel or process for reporting security issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.