The small dependency footprint, tests, changelog, and matching source repository support straightforward adoption. Lack of security scanning and unpinned workflow actions add maintenance hygiene concerns.
55%
Total Score
75
100
88
83
The package has had 9 releases since July 2019, but none in the last 12 months and its latest release was in March 2022. This long release gap is a meaningful maintenance concern.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with the absence of releases since March 2022. This is the strongest evidence of possible abandonment.
Composer is used for the build, but no security scanning tools are configured. The missing scanning is a hygiene gap, though it is less significant than the long maintenance pause.
The repository has no security policy. This weakens vulnerability-reporting transparency, especially for a package that records application data, but it is not by itself evidence of abandonment.
The single workflow was fully analyzed with no detected high-confidence findings or untrusted checkouts, but all 3 action references are unpinned. The missing top-level permissions block is acceptable on its own; unpinned actions remain a modest reproducibility and workflow-integrity concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.