The package has a matching repository, a declared GPL-3.0 license, and no install-time scripts. Its README is unfinished, and the repository has no security scanning, making future maintenance harder to assess.
38%
Total Score
0
71
75
The latest release was published in November 2020, and there have been no releases in nearly six years. That long gap is strong evidence of abandonment risk despite nine historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the unchanged release history and indicating no current maintenance.
The package includes a README, but it explicitly says usage is not documented; tests and a changelog are absent, which is normal for published artifacts and is not itself a gap.
Composer is used for project tooling, but no security scanning tools are configured. This leaves dependency and source changes with less automated oversight.
The repository has no security policy. For a small extension this is a secondary transparency gap, but it provides no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pozitronik/yii2-helpers Version * | — | — |
pozitronik/yii2-core-tools Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.