The MIT license, focused dependency set, matching repository, and usable README make the package straightforward to adopt. Its small project footprint and lack of security policy leave less support and transparency than a mature dependency should provide.
60%
Total Score
63
100
89
83
Only one registry account has publish access. That is a limited publishing base for a user-owned project and increases continuity risk when combined with the lack of recent activity.
The package has existed since 2018 with nine releases, but it has had no release in about two years and none in the last 12 months, indicating sharply reduced maintenance.
There were no commits and no active maintainers in the last three months, consistent with maintenance having stopped for about two years.
There were no new or closed issues or pull requests in the last month, while 13 pull requests remain open, suggesting limited current project attention.
The repository uses Composer build tooling, but no security-scanning tools were detected, leaving a modest transparency and maintenance-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.