The README, release notes, and matching source tree make integration and provenance clear. The single-user project has no recent activity or security policy, so long-term support is uncertain.
58%
Total Score
50
86
50
Only two releases exist, with the latest published about 15 months ago and none in the last 12 months. This limited and inactive release history raises maintenance uncertainty.
The repository recorded no commits and no active maintainers during the last three months, despite the repository remaining unarchived. That is meaningful evidence of currently inactive maintenance.
Composer build tooling is present, but no security-scanning tool was detected. This weakens automated oversight for a package with several runtime dependencies.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. The small scope may reduce exposure, but this remains a transparency gap.
The only workflow uses read-only permissions and has no reported dangerous audit findings, which is positive. However, both analyzed action references are unpinned, reducing build reproducibility and supply-chain assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
yiisoft/yii2-gii Version * | — | — |
kartik-v/yii2-grid Version ^3.0.4 | — | — |
kartik-v/yii2-mpdf Version ^1.0.0 | — | — |
kartik-v/yii2-editable Version ^1.7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.