Its README is brief and the four-file package provides little evidence of mature development. The declared license and package-to-repository match help, but there are no tests, security policy, or recent project activity.
30%
Total Score
0
71
67
Only two releases were published, both in April 2016, with no releases in the last 12 months; the latest release is about 10 years old. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package having seen no activity since April 2016. The long inactivity materially lowers maintenance confidence.
The artifact and repository each contain only four files, including a short README and no visible test or release-support structure. Such a minimal tree leaves little evidence of maintainability for a framework extension.
Composer is used for the build, which is appropriate, but no security-scanning tooling is present. This is a modest hygiene gap rather than evidence of a security defect.
The linked repository has no security policy. This is a transparency gap for a dependency, especially when the project also shows no recent maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.