A complete MIT-licensed package has tests, a substantial README, and a matching source repository. It has no security policy or scanning, so ongoing upkeep and response capacity are limited.
58%
Total Score
50
50
88
75
Ten runtime dependencies make this a moderately broad dependency surface for a Yii2 module, adding maintenance exposure, but the profile does not by itself indicate an excessive or unusual burden.
The registry namespace and repository owner match the same individual account, providing direct ownership continuity but no organizational backing beyond one person.
The package has 42 releases since December 2019, but none in the last 12 months; its latest release was in April 2023, over three years ago. This points to materially reduced maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with the package's long release gap and indicating current inactivity.
The repository uses Composer for builds, but no security-scanning tools were detected. The missing scanning is a modest transparency and maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0.20 | — | — |
kartik-v/yii2-grid Version ^3.3.0 | — | — |
bower-asset/autosize Version ^4.0.2 | — | — |
bower-asset/resumablejs Version ^1.1.0 | — | — |
yiisoft/yii2-bootstrap4 Version ^2.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.