It has a clear MIT license, a useful README, and only one Yii2 runtime dependency. The tiny repository has no tests or security scanning, limiting assurance for future changes.
61%
Total Score
50
100
88
75
One registry maintainer publishes the package. That is a thin operational base for a user-owned project and increases bus-factor risk, although it is not evidence of abandonment by itself.
The package has 9 releases over more than 11 years, but none in the last 12 months and the latest release was about 2 years ago. This points to materially reduced maintenance activity.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Together with the old latest release, this raises abandonment risk.
Composer is used for the build, but no security scanning tool is present. For this small package that is a modest assurance gap rather than a severe risk.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the package's small scope and single runtime dependency limit the significance of the gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.