The project has no security policy or automated security scanning, while seven pull requests remain open with no recent merges. The MIT license, matching repository, and stable release format help, but do not offset the maintenance risk.
38%
Total Score
50
81
75
The latest release was published in October 2019, and there have been no releases in the last 12 months. This long release gap is a meaningful abandonment concern, despite the package having four releases overall.
The repository has seven open pull requests but no new or merged pull requests in the last month, suggesting changes are not being actively integrated. There are no open issues, which is mildly reassuring but does not offset the stalled contribution activity.
Composer is used for the build, but no security-scanning tools are configured. The absence of scanning reduces maintenance assurance, although it is not evidence of a security incident by itself.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency and maintenance gap for a package that handles application and user-reporting workflows.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.1 | — | — |
sergios/yii2-worksection Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.