The repository has had no commits in the last three months, while 25 issues remain open and none closed recently. Tests, release notes, a substantial README, and an MIT license provide useful support, but the beta status and unpinned workflow actions add caution.
62%
Total Score
63
50
83
75
There were zero commits and zero active maintainers in the last three months. Although a release was published recently, the absence of recent source activity raises maintenance and abandonment concerns.
Ten runtime dependencies make this a relatively broad dependency surface for a code generator, increasing transitive maintenance exposure. The signal does not show an explicitly unsafe or excessive dependency pattern, so this is only a modest concern.
The repository has 25 open issues, four new issues in the last month, and no issues or pull requests closed or merged in that period. This indicates unresolved demand and weak recent follow-through.
The repository has nine stars and two forks, indicating a small user base. Popularity is only supporting evidence, so this modest adoption level does not materially outweigh the maintenance signals.
The project uses Make and Composer for builds, but no security-scanning tools are detected. This is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.48 | — | — |
fakerphp/faker Version ^1.9 | — | — |
cebe/php-openapi Version ^1.7.0 | — | — |
yiisoft/yii2-gii Version ~2.0.0 | ~2.1.0 | ~2.2.0| ~2.3.0 | — | — |
sam-it/yii2-mariadb Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.