It has one registry maintainer, no tests, and no security policy; the code is only four files. MIT licensing and a matching repository improve transparency, but support evidence is thin.
43%
Total Score
50
100
69
75
The package has had only two releases, both in July 2019, and none in the last 12 months; the latest release is about 7 years old. This is the strongest evidence of abandonment risk.
Only one registry account has publish access, and the project is user-owned rather than organization-backed. This creates limited publishing redundancy, although access records do not prove actual maintenance activity.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the complete absence of community signals reinforces the weak maintenance picture.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and hygiene gap rather than a standalone dependency blocker.
The repository has no security policy. For a small logging integration this is a limited gap, but it leaves no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.