Yii2 enterprise module
40%
Total Score
unhealthy
Risky: no release since March 2019, with no tests, changelog, or security policy.
Only two releases are recorded, and the latest was published in March 2019, with no releases in the last 12 months. That long period without a release is strong evidence of abandonment risk.
The artifact includes a license file and the repository also has one, so licensing is present. However, the manifest declares MIT while the detected file is BSD-3-Clause, creating a material mismatch.
The package runs post-install and post-update Composer scripts, adding install-time behavior that consumers must inspect and trust. No provided signal shows these scripts are harmful or necessary, so this is a supply-chain hygiene concern rather than a severe finding.
One registry account has publish access. Because the repository is owned by a user rather than an organization, the single-maintainer publishing base provides limited continuity if that person stops maintaining the project.
The package has no README, tests, or changelog, and the repository likewise reports no tests or changelog. The absence of tests and a changelog is not a packaging gap by itself, but the missing README reduces consumer transparency for this library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.13.1 | — | — |
bupy7/yii2-bbcode Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.