Its focused dependency surface and clear MIT licensing reduce adoption friction. Missing security tooling and policy leave less evidence for ongoing maintenance and response if problems arise.
44%
Total Score
50
100
75
50
The package has 22 releases since February 2016, but none in the last 12 months and its latest release was in October 2020. This long period without a release materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's multi-year release gap and indicating no observed current maintenance.
There was no new or closed issue or pull request activity in the last month, with one issue still open. This supports the broader evidence of an inactive project.
The repository uses Composer, which supports reproducible project setup, but it has no detected security-scanning tooling. That is a modest transparency and maintenance gap for a dependency library.
No security policy was found in the linked repository, leaving no documented process for reporting and handling vulnerabilities. This is a hygiene concern, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.