Its dependency set is fairly broad for a small Yii extension, and repository security practices are limited. The package has a README and license, but its release activity is exceptionally stale and recent commit activity is absent.
57%
Total Score
50
50
88
75
Eight runtime dependencies, including several UI and asset packages, create a relatively broad dependency surface for this small extension and increase upkeep burden.
Only one release exists, dated January 2020, with no releases in the last 12 months; this is a substantial maintenance and abandonment concern.
There were no commits and no active maintainers in the last three months, leaving current maintenance capacity unproven despite the repository not being archived.
Composer is used as the build tool, but no security scanning tools are reported, leaving a repository hygiene gap.
The repository has no security policy, reducing transparency about how vulnerabilities are reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.14 | — | — |
bower-asset/noty Version ^3.1 | — | — |
intervention/image Version ^2.3 | — | — |
seiweb/yii2-sortable Version ^1.0 | — | — |
kartik-v/yii2-widgets Version v3.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.