The published package includes a usable README, an MIT license file, and no install-time scripts. It has no tests, security scanning, or security policy, leaving limited evidence of ongoing quality control.
42%
Total Score
0
70
75
This package has only one release, published about 3 years and 6 months ago, with no releases in the last 12 months. That strongly indicates abandonment risk.
The repository has had 0 commits and 0 active maintainers in the last 3 months, and its last push was in March 2023. No newer maintenance evidence compensates for this gap.
Composer is used as a build tool, but the repository has no security scanning tools. This is a modest transparency and quality-control gap, not evidence of unfitness by itself.
The repository has no security policy, leaving no documented route for reporting or handling vulnerabilities. This adds a transparency concern for a package intended for application integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
yiisoft/yii2-httpclient Version * | — | — |
yidas/yii2-composer-bower-skip Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.