A clear BSD-3-Clause license, tests, and a matching organization-owned repository provide useful transparency. Its small dependency set and lack of install scripts reduce adoption friction, but they do not offset the maintenance gap.
43%
Total Score
50
100
72
83
The package has had no release in about 7 years and 9 months, with zero releases in the last 12 months. This is strong evidence of abandonment for a dependency.
There were zero commits and zero active maintainers in the last 3 months. Combined with the old last push, this indicates that fixes and compatibility updates are unlikely.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide no meaningful external adoption signal.
Composer is used for builds, which is appropriate, but no security scanning tools were detected. This is a hygiene gap that adds some transparency risk without proving the package is unsafe.
The linked repository is not archived, but its last push was in December 2018. The active archive status offers little compensation for the observed inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.6 | — | — |
yiisoft/yii2-bootstrap Version ~2.0.0 | — | — |
yiisoft/yii2-swiftmailer Version ~2.0.0 || ~2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.